Problem Summary
Users may receive emails or text messages that appear to come from legitimate organizations but are actually attempts to steal personal information, passwords, financial information, or other sensitive data.
Phishing attacks often use convincing messages, company logos, urgent language, and fraudulent links or attachments to trick recipients into revealing information or installing malicious software.
Environment
- Microsoft Outlook (Desktop, Web, and Mobile)
- Email applications on mobile devices
- Text messaging applications
- Faculty, staff, and students
Issue
Scammers use phishing emails and text messages to trick users into:
- Revealing usernames and passwords
- Sharing personal or financial information
- Opening malicious attachments
- Clicking fraudulent links
- Downloading malware
- Granting unauthorized access to accounts
Phishing attacks occur frequently and often imitate trusted organizations such as banks, utility companies, online payment services, government agencies, and educational institutions.
Resolution
How to Recognize Phishing
Phishing emails and text messages often tell a story designed to convince you to click a link, open an attachment, or provide sensitive information.
Common phishing tactics include messages that:
- Claim suspicious activity has been detected on your account.
- State there is a problem with your payment information.
- Request that you verify personal or financial information.
- Include an invoice or receipt you do not recognize.
- Ask you to click a link to make a payment.
- Advertise a government refund or rebate.
- Offer coupons, prizes, or free products.
Common Warning Signs
Be suspicious of messages that:
- Use a generic greeting such as "Dear Customer."
- Claim your account has been placed on hold.
- Create a false sense of urgency.
- Request passwords, financial information, or personal data.
- Contain unexpected attachments.
- Ask you to click a link to update payment details.
Legitimate organizations may contact you by email, but they generally do not ask you to provide sensitive information through links included in unsolicited emails or text messages.
How to Protect Yourself from Phishing
1. Keep Software Updated
Enable automatic updates whenever possible on:
- Computers
- Smartphones
- Tablets
Security updates often include protection against newly discovered threats and vulnerabilities.
2. Use Multi-Factor Authentication (MFA)
Multi-factor authentication adds an additional layer of security by requiring two or more forms of verification.
Authentication methods generally fall into three categories:
-
Something you know
- Password
- PIN
- Security question
-
Something you have
- Verification code sent by text or email
- Authenticator application
- Security key
-
Something you are
- Fingerprint
- Facial recognition
- Retina or biometric scan
Even if a scammer obtains your password, MFA can help prevent unauthorized access to your account.
3. Back Up Your Data
Regularly back up important information:
- Store backups on an external hard drive.
- Use approved cloud storage solutions.
- Back up data on both computers and mobile devices.
Backups can help recover your information if malware or ransomware damages your files.
What To Do If You Suspect a Phishing Attempt
If you receive a suspicious email or text message:
- Stop and evaluate the message.
- Ask yourself:
- Do I have an account with this company?
- Do I know the person who contacted me?
- If the answer is No:
- Do not click links.
- Do not open attachments.
- Report the message.
- Delete the message.
- If the answer is Yes:
- Contact the company directly using a trusted phone number or website.
- Do not use contact information provided in the suspicious message.
Malicious links and attachments can install harmful software on your device.
Report a Suspicious Email from a Mobile Device
- Open the email you want to report.
- Tap the ⋮ (More Options) menu in the upper-right corner.
- Select Report Junk.
- Choose the appropriate option:
- Junk – Unwanted or spam messages.
- Phishing – Messages attempting to steal personal information.
- Block Sender – Prevent future messages from that sender.
What To Do If You Responded to a Phishing Email
If you believe you provided sensitive information to a scammer:
Personal Information Was Shared
If you shared information such as:
- Social Security Number
- Credit card number
- Bank account information
Visit IdentityTheft.gov and follow the recommended recovery steps based on the information that was exposed.
You Clicked a Link or Opened an Attachment
- Update your device's security software.
- Run a full malware or antivirus scan.
- Remove any threats identified by the scan.
- Change passwords for affected accounts.
- Notify your organization's IT support if the account is work-related.
Expected Result
Users can:
- Identify common phishing attempts.
- Avoid interacting with malicious links and attachments.
- Report suspicious email messages appropriately.
- Protect accounts through MFA and regular software updates.
- Take immediate action if a phishing attack is suspected or successful.
Cause
Phishing attacks rely on social engineering techniques that exploit trust, urgency, fear, curiosity, or financial incentives to convince users to take actions that compromise security.
Attackers frequently impersonate trusted organizations and individuals to increase the likelihood of success.
Additional Information
Helpful Resources
Security Best Practices
- Never provide passwords through email.
- Verify requests for sensitive information through trusted channels.
- Be cautious of unexpected attachments.
- Keep operating systems and applications updated.
- Use unique passwords for important accounts.
- Enable multi-factor authentication whenever available.
Support Contact
For further support, contact Employee Technical Support Monday through Friday, 8:45 AM to 4:45 PM at (585) 292-TECH (8324).
Keywords
phishing, phishing email, phishing text, scam email, spam, cyber security, malware, suspicious email, report junk, report phishing, block sender, MFA, multi-factor authentication, identity theft, social engineering, email security, fraud prevention, cybersecurity awareness, Outlook Mobile, spam protection