Skip to main content
⚠️ Emergency Guide

I Clicked a Phishing Link — What Now?

Don't panic. Take these steps in order — the first two are the most important.

1

Don't click anything else on the page

Immediate

Close the browser tab immediately. Do not enter any usernames, passwords, or payment details on the page that opened.

2

Change your email password

Within 5 minutes

Go to your Gmail account settings and change your password now. If you used the same password elsewhere, change those too. Use a unique password for each account.

3

Enable two-factor authentication

Within 10 minutes

Turn on 2-step verification for Gmail at myaccount.google.com. This means even if someone has your password, they can't access your account without your phone.

4

Check your Gmail for suspicious activity

Within 30 minutes

Scroll to the bottom of Gmail and click "Details" to see recent activity. Look for logins from unknown locations. Check your Sent folder for emails you didn't send.

5

Scan your inbox for more phishing

Today

Phishers often send multiple attempts. Scan your inbox to find and delete any other phishing emails before you accidentally click one.

6

Report the phishing email

Today

In Gmail: open the phishing email, click the three dots (⋮), and select "Report phishing". Also forward it to reportphishing@apwg.org to help protect others.

Scan your inbox for more phishing

Gorganizer analyzes 1,751+ signals to detect phishing emails, spoofed senders, suspicious attachments, and scam patterns — and removes them safely.

Scan my inbox for phishing →

Nothing is permanently deleted — 30-day recovery window