If you paid or gave card details
- Call your bank immediately — the number on the back of the card or in the app
- Block the card and ask whether the payment can be stopped
- Change your online banking password and review recent transactions
- Keep screenshots, messages and numbers as evidence
If you entered a password on a fake page
Change that password at once — and everywhere you used the same one. Turn on two-factor login, log out of all sessions and check the account’s recovery email and phone. If it was your email, check the forwarding rules too: attackers like to add silent forwarding.
If it happened at work
Report it to IT or your manager immediately — even if you’re embarrassed. The first minutes decide whether a single click becomes a company-wide incident. A data leak involving personal data may have to be reported to the Information Commissioner within 72 hours, so the company needs to know quickly.
If you pasted confidential data into AI
Delete the conversation, check whether training on your data is switched on and turn it off, and tell whoever is responsible for data protection. It is not always a disaster — but the company must be able to assess it.
Where to report in Slovenia
- SI-CERT (cert@cert.si) — phishing, online fraud, hacked accounts; advice at varninainternetu.si
- Police (113) — fraud and threats are criminal offences
- Information Commissioner — personal data breaches
- The platform itself — fake profiles, ads and deepfakes