PhishingLearn to identify common scams and traps.
Can I report a phishing scam?
If you would like to report a phishing attempt related to a University unit or service, or you have questions about the validity of an email you have received, please contact email@example.com.
You may report scams to the federal government at firstname.lastname@example.org, which collects information to build cases against phishers. You may also contact the Anti-Phishing Working Group, a volunteer organization committed to wiping out phishing scams.
What Is a Phishing Scam?
A phishing scam is a legitimate-looking email that appears to come from a well-known and trustworthy organization or website but is really an attempt to gather personal and financial information from a recipient. Although this article focuses on email scams, remember that phishing scams can come in other forms too, such as via fax.
Two Common Types of Phishing Scams
The first type of scam asks you to respond to an email with your account password or Social Security number in order to prevent immediate closure of your bank account, email account, or some other service. No reputable organization will ever send an unsolicited message requesting this kind of information. If you ever receive a message that asks you to send in your CNet password, for example, it is a fraudulent email.
The second type of scam asks you to click a link to a fake site that might somewhat resemble a site or service you actually use, and log in with your password to verify your account. UChicago IT Services will never request your password, nor will we ask you to change or “validate” your password at a site URL other than http://cnet.uchicago.edu. You should never use your CNetID to log in at a domain other than myaccount.uchicago.edu.
If you’ve responded to either of these types of scams, you’ve placed your personal information in the hands of scammers, who can misuse it.
How do I know if a message I received is a phishing attempt?
Review the simple guidelines for identifying phishing emails included below.
Be suspicious of any email with urgent requests for personal information.
Phishers typically include upsetting or exciting (but false) statements in their emails to get people to react immediately. They typically ask for information such as your username, password, credit card numbers, social security number, or date of birth. Phishing emails will are usually worded generically, although occasionally phishers will go to the trouble to personalize them to make them seem more credible. If you receive an email requesting any kind of personal information, verify the source of the request by calling the person or organization in the From field before you respond or open any attachments.
Never share passwords, personal information, or financial information over email.
You should only provide private information such as credit card numbers or account information using a secure website or telephone. Email is not a secure way to send sensitive information.Never email your password, personal information, or financial information. Likewise, because there is no way to check the security certificate of pop-up windows, do not use them to provide sensitive information even though they may look official or claim to be secure. Close pop-up windows by clicking the X in the top right corner. Do not click a Cancel button on a pop-up; it may be a trap!
Do not click links in email messages if you suspect the message might not be authentic or if you don’t know the sender.
Always verify the real target address of a link by hovering the mouse over the link before clicking it, or type the link yourself in your browser window.
Don’t trust offers that seem too good to be true.
What’s too good to be true is probably too good to be true. If you don’t remember a relative, you probably don’t stand to inherit millions of dollars from him or her. If you don’t remember entering a lottery, you probably haven’t won anything. Exercise common sense before responding.
Recent Phishing Scams
Subject: Email Alert !!! Date: Sun, 20 May 2018 18:21:35 +0000 From: "Shauna McInnes" Urgent technical notification to all Employee,Faculty & Staff. An account submission routine is in schedule this is as a result of unidentified activity in our database. kindly click...read more
From: Office Mail [mailto:email@example.com] Sent: Thursday, May 17, 2018 9:15 AM To: Recipients Subject: Warning!!! This notification is to inform account operators to confirm your verification to avoid account shut down because if you receive this email your...read more
Date: Thu, 17 May 2018 06:20:08 +0000 Subject: 15.1GB From: "Walls, Nathaniel" To: "Walls, Nathaniel" IT Administrator has currently upgraded all mailboxes (size to 15.1GB). Please upgrade your account by clicking on Faculty & Staff Email Upgrade. Thanks Help Desk...read more