Phishing: What to do After Suspected Phishing

If you received a phishing email and clicked on any of the links or sent any personal information in response, follow these steps to ensure that your account and data are secure. Learn more about Malware and phishing attacks.  

After Phishing

  1. Report the Phishing Message.
  2. Call or visit the Helpdesk immediately for assistance in securing your account. It is critical that ITS staff investigate, contain, and remediate any damage that may have been caused by any unauthorized access.
  3. Change your Carleton password (link opens in a new tab).
    • If your account is compromised and you are locked out, this step will not work. In that case, contact the Helpdesk.
  4. Log out of all of your active Google Sessions from Google's Manage Devices page (link opens in a new tab).
  5. Log out of ALL your Google Accounts: On the device that you clicked on the link or sent the information from, sign out of all of your Google accounts (on the Google website, in Google apps, etc).
    1. Select your portrait in the top right corner of any Google page.
    2. Select Sign out.
    3. Do the same for any other Google accounts you are signed into on your computer.
  6. Run a ThreatDown (aka Malwarebytes) Scan (if you're on a Carleton-provided computer):
    1. Right-click on the Malwarebytes Icon Stylized M or ThreatDown Icon icon in your taskbar area, near your computer's clock.
    2. Select Start Threat Scan.
  7. Check your Gmail filters. Navigate to Settings > See all settings > Filters and Blocked Addresses to make sure the attacker hasn't added or tampered with your filtering or blocked addresses in any way.

Technician Note: see internal instructions

Need Help?

Please contact the ITS Helpdesk for assistance: go.carleton.edu/helpdesk or 507-222-5999.

Was this helpful?
0 reviews