US blog
Recovery

Safe password steps after a suspicious AI call

If a suspicious AI voice call led to a code, link, app install, or account warning, use these password and account safety steps.

Password manager and account security checklist after a suspicious call

If a suspicious call made you share a code, click a link, install an app, or log in somewhere, treat the account as exposed.

Start with the account the call was about: bank, email, Apple ID, Microsoft, phone carrier, or social account.

Then secure the email account attached to it. Email is often the reset key for everything else.

The password order

  1. Email.
  2. Bank or payment apps.
  3. Apple ID or Google account.
  4. Phone carrier account.
  5. Password manager.
  6. Social accounts.

Use a unique password for each account. If you reused the same password anywhere, change it there too.

What makes a safer password

NIST guidance has moved away from old "change it every 90 days and add symbols" habits. The practical version for a normal person:

Change the login, then remove the intruder

After changing the password:

When to call the bank or carrier

Call the bank if:

Call the carrier if:

Sources