It looked real. The logo was right, the layout was convincing, maybe it even had reviews and a working "contact us" page. But the URL was wrong, and now you're wondering what happens next. The honest answer: it depends on exactly what you typed in.
What did you enter?
Email and password
Treat both as compromised right now, even if the site "looked fine" afterward. Follow the full playbook in Someone Has My Password — What to Do Right Now: change the password on the real site, sign out other sessions, and turn on MFA.
Credit or debit card number
Call your bank right now, using the number on the back of the card, and request a block. This is the one category where minutes genuinely matter — the faster the card is blocked, the fewer charges go through before your bank's fraud systems catch it independently.
National ID or passport number
This carries identity-theft risk, not just account risk. File a police report (having a report number matters if someone opens credit or accounts in your name later), and if your country has a credit-freeze or fraud-alert mechanism, use it — it stops new accounts being opened in your name without extra verification.
Phone number
Expect follow-up phishing calls and texts referencing what you "signed up for." Don't confirm or deny anything to an inbound caller — hang up and, if it claims to be your bank, call the number on your card instead.
Just your name and email
Lower risk on its own, but expect an uptick in spam and more convincingly personalized phishing attempts, since the scammer now knows your name and a working inbox to target.
Not sure how exposed you are?
Tell Nerva IR what you entered and where, and it'll build a recovery plan matched to exactly that — not a generic checklist.
How to tell a fake website from a real one
- Check the URL carefully. "amaz0n-support.com" and "paypal-secure-login.net" are not the real domains, even though they contain the brand name.
- The padlock icon doesn't mean "safe." It only means the connection is encrypted — scammers can and do get padlocks on fake sites too.
- Check how new the domain is. A site claiming to be a decade-old bank that was registered three weeks ago is a major red flag.
- Search "[company name] + scam" before entering anything sensitive. If others have been caught out by the same fake page, this usually surfaces it fast.
Report it
Reporting helps even when you can't undo what already happened — it feeds databases that protect the next person and can help law enforcement connect your case to a wider pattern. Report the site itself to Google Safe Browsing so it gets flagged for other visitors, tell your bank if any financial details were involved, and file with your local police or national body — INCIBE in Spain, Action Fraud in the UK, or the FBI's IC3 in the US.
The Anti-Phishing Working Group tracks these fake-site campaigns at scale, and their trend reports are a useful reality check: this happens to a lot of careful people, not just careless ones.