Recovery
Safe password steps after a suspicious AI call
If a suspicious call made you share a code, click a link, install an app, or log in somewhere, treat the account as exposed.
Start with the account the call was about: bank, email, Apple ID, Microsoft, phone carrier, or social account.
Then secure the email account attached to it. Email is often the reset key for everything else.
The password order
- Email.
- Bank or payment apps.
- Apple ID or Google account.
- Phone carrier account.
- Password manager.
- Social accounts.
Use a unique password for each account. If you reused the same password anywhere, change it there too.
What makes a safer password
NIST guidance has moved away from old "change it every 90 days and add symbols" habits. The practical version for a normal person:
- Use long passwords.
- Make every important account unique.
- Use a password manager.
- Do not reuse passwords.
- Change passwords after a suspected compromise.
- Prefer phishing-resistant authentication where available.
Change the login, then remove the intruder
After changing the password:
- Sign out of other devices.
- Remove unknown recovery emails or phone numbers.
- Check forwarding rules in email.
- Remove unknown app permissions.
- Turn on app-based authentication or passkeys where available.
When to call the bank or carrier
Call the bank if:
- You shared a one time code.
- You entered card details.
- You see a transfer or charge.
- The caller told you to move money.
Call the carrier if:
- Your phone loses service.
- You see a SIM change you did not request.
- You stop receiving codes.
- Someone says they received messages from "you."
Sources
- NIST SP 800-63B, authentication guidance: https://pages.nist.gov/800-63-4/sp800-63b.html
- FTC, what to do if you were scammed: https://consumer.ftc.gov/articles/what-do-if-you-were-scammed
- TIME coverage of FBI advice on AI vishing: https://time.com/7301176/impersonation-ai-voice-vishing-scam-rubio-wiles-trump-fbi-advice/