Local Tool
Phishing response plan
Order the first actions after the suspicious message. Select a situation; do not enter passwords, codes or account details here.
Do not give any more details to the caller. If the bank data has been disclosed or an unknown payment has been made, please contact the bank via its official channel.
Start by stopping contact
Do not reopen the suspicious page. Check the case by a known application or contact determined independently of the message. Please inform the administrator on the equipment or business account.
The plan helps to organize the operation. It does not diagnose the device, recovers the account and does not perform the notification. Selection of the situation and selections are temporary; they disappear after leaving the page.
Only received a message
Check request with an independent channel
You do not need to open the link to determine if the case is true.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
Do not answer by code, password or payment details. Save message to report.
Enter the service yourself. The phone number is determined from an independent source, not from a message.
How to check suspicious message →Use the platform mechanism. In Poland, a suspicious SMS can be transmitted in unchanged content to 8080.
Application instructions for CERT Poland →Do not send the active link to your friends. Use the organization procedure with your business account.
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Link opened, no data provided
Close the page and see what happened
The opening of the link itself does not confirm the acquisition of the account. Also check the downloads and permissions given.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
Do not continue the form or conversation with the person who provided the link.
If you download a file, do not run it. Undo unwanted permissions, e.g. notifications, in the browser settings.
Use system or official store settings. Do not install “update” from the suspicious page.
Updates without traps →If an installation, remote access request or data is given, select the appropriate variant of this plan.
How to report phishing →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Password, code or approved login
Secure your account through the right service
The entered data may have been sent to the page before sending the form. The code or approval could have already been used.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 5.
Use a known application or address. If you suspect an infection, use another device. For banking first contact the bank.
Set a new unique password. Use the official recovery procedure if you cannot log in. The change of password itself may not end all sessions.
Account security step by step →Browse 2FA, passkeys and connected applications. Also check the transfer and rules in the mail. Delete access you do not recognize.
Each account needs a separate password. Start with the mail and accounts through which you recover other services.
Inform the supplier, and with the administrator's business account. The application to CERT does not change the password or recover the account.
How to check your account sessions →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Details of payment or transfer were provided
Contact the bank now
Use the card number, the known application or the official website. Do not use the contact provided by the caller.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
Describe what has been given or approved. Set with the bank a card block or access and possible payment actions.
Do not enter any more codes or transfer “to a secure account”.
Write down the time and transaction identifier in a safe place. Do not enter the card number, password or document data here.
If you lose money, report the case to the police. Suspected website or message report CERT Poland. The application does not guarantee the recovery of funds.
Phishing notification channels →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
PESEL, data or photo of the document
Check identity protection by official way
Do not send any more photos or data to “cancell” the previous operation. Do not enter the PESEL number or document here.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
For an adult with the PESEL number, an official reservation service is available. Read its scope and rules on Gov.pl; it does not block all possible ways of using data.
Official statement of reservation of the PESEL number →If you suspect unauthorised use of the evidence, check the procedure for notification to the municipality. Cancellation of the evidence has consequences for the validity of the document; follow official instructions.
Gov.pl — identity theft report →If you have a suspicious contract or payment, please contact the official canal institution.
Revealed information can be used for credible-looking messages. Do not trust the person who offers paid “recovery” by the same contact.
How to report phishing →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Downloaded file, but not launched
Do not open downloaded file
Do not check the file by trying to run it. The comparison of the control sum does not assess whether the program is safe.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
Do not turn on macros or execute pasted commands from messages or “verification”.
Use trusted, up-to-date security software. Scan result does not give you a full safety guarantee.
First contact the administrator on your business equipment. Do not upload confidential files to an accidental online scanner.
Follow the response team instructions. However, if a file is started, select the installation variant.
How to report a message →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Start file, command or remote access
Secure accounts from another device and ask for help
Uninstalling a single program alone may not remove the effects. Follow up with technical assistance.
You declare your own steps. The selections are not a confirmation of the security of your account or device.
Selected steps: 0 of 4.
Do not follow the caller’s instructions again. Please inform the administrator immediately on your business device.
Change your revealed passwords and end unauthorized sessions. Start with mail. Please also contact the bank at banking or payments.
Mail security →Use trusted technical assistance or organization procedure. Do not log in to important services from a suspicious device before explaining the situation.
Save the time and name of the running program in a safe place. Do not publish secrets or files containing other people's data.
Report to CERT Polska →
All steps checked. Follow further notifications and follow the supplier’s instructions or technical assistance. This list does not confirm the end of the incident.
Sources and further instructions
The options are the author's order of the first actions. Details depend on the service and the device. Sources were checked on October 3, 2026.
- Gov.pl — reservation of the PESEL number
- Gov.pl — Report of unauthorised use of evidence data
- CERT Poland — phishing diagnosis and data response
- CERT Poland — intercepted mailbox
- CERT Poland — Incident reporting channels
- FTC — Phishing and Harmful Software Upon Click
- Google — Security of the account taken