Short answer
What to do right now
Go directly to the real service now—through its known app or an address you already use. Change the password, then protect any other account where you reused it.
Immediate actions
Secure the affected account now.
Open the real service through a known app or address. Use another trusted device if you suspect someone had device access.
Change the password, then change it anywhere else you reused it.
Sign out other sessions or devices if the service offers that control.
Check recovery email, recovery phone, linked devices, and recent activity; turn on multi-factor authentication.
If you cannot sign in, use the provider’s official account-recovery process.
Do not
Avoid making the situation harder.
- Do not use a recovery link or phone number from the suspicious message.
- Do not approve a new sign-in or share a new verification code with the sender.
Records and reporting
Keep the details you already have.
Save the original message and record password changes, unfamiliar sessions, recovery-detail changes, and case numbers.
Source notes
Official guidance behind these steps
Plainly Living uses the scope and exceptions recorded in its claim-control ledger. These links go to the responsible public agency.
Plainly Living