
Phishing attacks are not always obvious. Cybercriminals increasingly use convincing messages that may appear to come from a colleague, university department, familiar organization, or trusted service. A message can look legitimate while still being designed to compromise your account, obtain sensitive information, or gain access to university systems.
For this reason, do not assume an email is safe simply because it looks professional or comes from a familiar sender. Before clicking a link, opening an attachment, or responding to an unexpected request, take a moment to consider whether the message is legitimate and whether the requested action is appropriate.
The examples on this page illustrate common phishing techniques and warning signs to watch for. Reviewing these examples can help you recognize suspicious messages—even when they are designed to look routine or trustworthy.
Avoid clicking links or providing information until you have confirmed the request through a trusted method. If something seems unusual, unexpected, or simply does not feel right, report it to your university’s IT or information security team.
Your attention is an important part of protecting yourself, your colleagues, and the university community.
Click here to see currently circulating spam and phishing emails