Pinzen
GuidesUse casesFAQSupportOpen Pinzen
  1. Home
  2. Guides
  3. I Gave a Scammer My Password: What to Do in the Next Hour

Breaches and Hacked Accounts

I Gave a Scammer My Password: What to Do in the Next Hour

I gave a scammer my password or a verification code. What now? A calm plan for the next hour to lock them out, protect your money, and report it.

Last updated October 4, 2026 · 8 min read
On this page
  1. I gave a scammer my password: the first 10 minutes
  2. If you also shared a verification code
  3. Check for changes the scammer made
  4. Report it, and keep a record
  5. If it happened to a parent or grandparent
  6. Making the next scam bounce off
  7. Frequently asked questions

If you gave a scammer your password, change it now from a device you trust and sign out of every other device. If it was your bank login or card details, or you sent money, call your bank first, using the number on the back of your card. Acting fast limits the damage, so take a breath and follow the steps below.

That sinking "I gave a scammer my password" feeling happens to careful, smart people every day. Scammers are skilled at rushing you, whether by phone, text, or a phishing site (a fake page dressed up as a real company's). You are not foolish, and this is fixable.

I gave a scammer my password: the first 10 minutes

Figuring out how it happened can wait. Do these things first.

  1. Stop talking to the scammer. Hang up, close the chat, and don't reply. Don't call back any number they gave you.
  2. Get them off your device. If they had you install a remote-access app (one that lets someone control your screen), close it, turn off Wi-Fi, and switch to another device. Later, uninstall the app and run a security scan.
  3. If money is involved, call your bank first. That means a bank login, card number, or payment you already sent (see what to say below).
  4. Go to the real site yourself. Type the address or open the company's official app instead of tapping links in the message.

Change the password and sign out everywhere

Change the password you gave away. Make it long and new, not the old one with a number added. Four random words work well, or let a password manager create one.

Next, look for a setting like Sign out of all devices or Manage devices, and use it. Changing a password doesn't always kick out someone who's already signed in.

Then turn on two-step verification (also called 2FA) if it's off. It means the site asks for a second proof after your password, like a code or a tap on your phone.

Once a scammer has your password, they often try it on other sites, so change it anywhere else you used it. Start with:

  • Your email, because it can reset almost everything else
  • Your bank, card, and payment apps
  • Your Apple, Google, or Microsoft account
  • Shopping sites with a saved card
  • Social media

If the scammer already changed your password, use the site's Forgot password link, or its account recovery page if that fails. Our guide on what to do if your email is hacked walks through getting an account back.

Call your bank if money could be at risk

Use the number on the back of your card or on your bank's official website, never one from a text, email, or caller. A fake "fraud department" is one of scammers' favorite tricks.

Here's what to say:

"I've been scammed, and someone may have my online banking login or card details. Please help me lock my account and cards, check recent activity, and change my login."

If you already sent money, say that first and ask whether they can stop the payment or try to get it back. Then ask them to:

  • Check recent activity, including pending payments
  • Freeze or replace any card the scammer saw
  • Look for new payment recipients, raised limits, or changed contact details
  • Give you a case number and explain how to dispute charges

A bank can sometimes stop a payment or pull back a transfer if you call quickly, but its options shrink once the money has moved on. If you paid with a gift card, wire service, or payment app, contact that company right away too.

If you also shared a verification code

A verification code, also called a one-time code, is the short number a site texts or emails you, or that an authenticator app on your phone shows, to prove it's you. If you shared it, the scammer may already have used it to sign in, reset your password, or approve a payment.

A common line is, "I sent you a code by mistake, can you send it back?" There's no mistake: the scammer needs that code to get into your account or open one in your name.

If you shared a code:

  1. Check the message the code came in. It usually names the company, so you know which account to secure first.
  2. If the code came from your bank, call the bank first. Then change that password, sign out of all devices, and check for the changes below.
  3. Read our guide to verification code scams so the pattern is easy to spot next time.

Check for changes the scammer made

If a scammer got into your account, they may have made quiet changes to get back in later. Set aside 15 to 20 minutes to check each account's security settings, starting with email, and fix anything you didn't set up:

  • Recent sign-ins from devices or places you don't recognize
  • A changed recovery email or phone number, which would let the scammer reset your password again
  • Email forwarding or filter rules that send your mail elsewhere or hide security alerts
  • Connected apps and devices you don't know
  • Two-step verification methods you didn't add, such as an unknown phone number or passkey
  • New payment recipients, orders, or shipping addresses in banking and shopping accounts
  • Messages you didn't send. If you find any, warn your contacts.

If you still can't get in, contact the company's support through its official website or app, not search ads, which scammers also buy. If your details were also in a company data leak, our data breach checklist covers the wider cleanup.

Report it, and keep a record

Once your accounts are safe, take 10 minutes to report it, even if you didn't lose money. First, while it's fresh, write down:

  • When and how the scammer contacted you, including any phone number, email, or website they used
  • What you shared, such as a password, code, or card number
  • Any money you sent, how, and to whom
  • Screenshots of the messages

Then report it:

  • To your bank or card company, if money or card details were involved
  • To the company that runs the account, through its hacked-account or fraud page
  • To your government's fraud reporting service. In the US, that's the FTC at ReportFraud.ftc.gov. Elsewhere, search for your country's official site.

If you shared your Social Security number or other ID details, the FTC's IdentityTheft.gov gives you a step-by-step recovery plan. A free credit freeze, which stops new lenders from seeing your credit report, makes it much harder for a scammer to open accounts in your name.

If it happened to a parent or grandparent

When a parent tells you they were scammed, they need calm first, not a lecture. Many people feel deeply embarrassed, and some hide a scam rather than admit it, which is exactly what scammers count on.

  • Start with kindness. Try, "I'm glad you told me. This happens to lots of people, and we can fix it."
  • Work through it side by side. Let them do the typing if they'd like, so they stay in charge.
  • Make the bank call together. The bank will usually need to hear from your parent, but you can be right there to help.
  • Warn them about follow-up scams. People who've been scammed are often targeted again, including by fake "recovery services" that charge a fee to get money back.
  • Agree on a simple rule. For example: "If anyone asks for a code or a password, hang up and call me."

For more ideas, see our guide to protecting elderly parents from phone scams and fake logins.

Making the next scam bounce off

A few habits make scams much less likely to work:

  • Never share a code or password with anyone who contacts you. Real companies don't call or message out of the blue asking for either.
  • Slow down when you feel rushed. Urgency is a scammer's main tool, so hang up and call the company on a number you look up yourself.
  • Give every account its own password. Then one stolen password can't open the others.
  • Use passkeys where you can. A passkey signs you in with your face, fingerprint, or screen lock instead of a password. It only works on the real site, and there's nothing to read out to a caller. See our plain-English guide to passkeys.
  • No passkey option? Prefer an authenticator app to text codes. Someone who hijacks your phone number can't intercept its codes.

A password manager helps here too. Pinzen's browser extension for Chrome, Edge, Brave, and Firefox fills a login only after you click, and only on the exact secure (HTTPS) site it was saved for. On a lookalike page, it won't fill, which is your cue to stop and check the address.

You can create a free Pinzen vault to try it. The free plan includes one private vault on one trusted device at a time, password import, the autofill extension, and a health check that flags weak, reused, and exposed passwords.

No tool replaces your judgment or makes you immune to scams. But unique passwords and two-step verification turn a moment like this into a small fix instead of a crisis.

Frequently asked questions

What should I do if I gave a scammer my password?

Change that password from a device you trust, sign out of all other devices, and change it anywhere else you used it. If your bank login, card, or money is involved, call your bank on the number on your card. Then check the account for changes and report the scam.

Can a scammer get into my account with just my password?

Often, yes, if the account doesn't use two-step verification. If it does, they also need your code or approval, which is why scammers so often ask for it. Change the password either way, turn on two-step verification, and never approve a sign-in prompt you didn't start.

What happens if I gave a scammer a verification code?

They may have used it right away to sign in, reset your password, or approve a payment, so treat that account as taken over. Change the password, sign out everywhere, and remove recovery details or devices you don't recognize. If the code came from your bank, call the bank.

Should I report a scam if I didn't lose money?

Yes. Reports help banks, companies, and investigators spot patterns and warn others. They also create a record that can help you if your details are misused later. In the US, report it to the FTC at ReportFraud.ftc.gov. Most countries have a similar official reporting service.

Keep your family's passwords in one safe place

Pinzen is free to start. Sign up with Face ID, save your Recovery Kit, and share only what you choose.

Create a free vault

Keep reading

Breaches and Hacked AccountsHow Often Should You Change Your Password? What Experts Say Now7 min readBreaches and Hacked AccountsIs Have I Been Pwned Safe? How Password Checks Stay Private7 min readBreaches and Hacked AccountsMy Email Was in a Data Breach: What It Means and What to Do8 min read
Pinzen

A private place for the passwords your household depends on.

ProductFeaturesFamily use casesGuidesPlatformsPricing
ResourcesFAQSecurityHelp & supportShare your story
LegalPrivacy policyTerms of use© 2026 Pinzen