Everyday security · Unit 01 · Lesson 6 of 6
When things go wrong
A calm next step is a skill. Practice recovering and asking for help.
After this lesson you can
- choose a proportionate next step after a suspicious interaction
- find recovery help through an official channel
- explain why account recovery includes sessions and recovery settings
You realize the sign-in page looked wrong just after pressing submit. Take a breath. You do not need to solve the whole incident at once.
Stop interacting with the suspicious page or person. Then choose a next step based on what actually happened. A mistake is something to respond to, not something to hide.
Match the response to the situation
Only opened a link? Close it. Check whether something downloaded, an app opened, or you granted a permission. A click alone does not prove compromise. If a file ran or you are unsure, use trusted device support. Keep software updated.
Entered a password or code? Open the real service independently. Change an exposed password promptly, and change it anywhere else you reused it. Review active sessions and use “sign out of all devices” where available. If you cannot sign in, start the provider’s official recovery process.
Check recovery email addresses, phone numbers, and security methods. For email, review forwarding rules too. A password change may not undo every change someone already made.
Sent money or payment details? Contact your bank or payment provider promptly using a known route. Explain what happened and ask about available protections.
Ask for help with useful facts
On a work or school device, contact the support or security team promptly and follow their instructions. Share what happened, when, and what you clicked or entered. Do not include passwords or verification codes in the report.
Takeaway: Stop, use a trusted route, and get help early. Recovery is a normal security skill.
Terms you met
Check yourself
No timer. No penalties. Read the explanation and try again whenever you like.
This lesson’s questions have changed. Your reading progress is saved; review the updated questions.
-
You opened a suspicious link but entered nothing. What can you conclude?
Show the answer
Correct answer: Close it and check whether anything downloaded or was permitted. Choose the next step based on what you actually did. Seek trusted help if a file ran or you are unsure.
-
You entered your password on a suspicious page. What is a useful next step?
Show the answer
Correct answer: Open the real service independently and secure the account. Change the exposed password, review sessions, and use official recovery help if locked out.
-
You changed an exposed password. What else deserves attention?
Show the answer
Correct answer: Active sessions, recovery details, and any accounts that reused it. A password change may not end every session or undo changes already made.
-
A suspicious attachment ran on a work laptop. What should you do?
Show the answer
Correct answer: Stop interacting with it and contact your support team promptly. Describe what happened and follow their response instructions; do not improvise a cleanup.
Try it
- WriteWrite a fictional help request: ‘I entered a password on an unfamiliar page at about 10:00. I stopped using the page. I need help checking the account.’ Do not include the password, codes, or personal records. Add the trusted support route you would use.