Skip to content
ScamVictimLawyer

Reset your passwords after a scam

You are not sure which passwords a scam may have exposed.

Updated 2026-09-29 · Independent resource. Legal review pending.

Start with email, not banking

Change your email password first, even before your banking password, since email is usually the key to resetting everything else. If a scammer still holds access to your email, any other password you change can simply be reset again.

Log in from a device you trust, and check whether the recovery email or phone number on the account has been changed. Update it back if it has.

Turn on two-factor authentication on your email account if you have not already, since this is the single most effective step you can take here.

Work through banking and payment accounts next

Once email is secured, move to banking apps, e-wallets, and any payment platform you use. Change each password individually, even if it feels repetitive, rather than assuming one change covers everything.

If a phishing page or a suspicious app was involved, treat every account accessed on the same device as potentially exposed. Read account takeover for the fuller list of what to check beyond passwords alone.

Do not reuse the same password again

If the exposed password was used on more than one account, that weakness now applies everywhere it was reused, not only on the account the scam targeted directly. Change it on every account it appears, not just the obvious one.

Choose a different password for each account going forward, even if it feels harder to remember. A password manager can generate and store these safely, which is far more reliable than a small set of passwords used repeatedly.

Turn on extra verification everywhere you can

Enable two-factor authentication on every account that offers it, starting with email, banking, and anything linked to payments. This adds a step a scammer usually cannot complete without your device, even if a password becomes known later.

Check social media and messaging apps too, since these are often used to reach your contacts or gather more information about you.

What to do next

Work through the list in order rather than trying to secure everything at once, since email and banking matter most. Watch your accounts for unfamiliar activity over the following weeks.

For the wider set of first actions after a scam, read the first response overview.

If you are not sure which accounts still need a new password, tell us what happened and we will help you work through the list in order.

Common questions

Why should I change my email password before my banking password?

Email is often used to reset every other account, including banking. If a scammer still has access to your email, changing your banking password alone will not fully lock them out, since they could simply reset it again.

Is it enough to change just one password if I reused it elsewhere?

No. If the same password was used on other accounts, change it everywhere it appears, not just on the account directly affected by the scam. A single reused password can undo the protection of an otherwise secure account.

How do I remember different passwords for every account?

A password manager can generate and store a different password for each account, so you do not need to remember them all. This is safer than reusing a small set of passwords across many accounts.

If you are not sure which accounts still need a new password, tell us what happened and we will help you work through the list in order.