Skip to content

Protect Yourself From Phishing

What Is Phishing?

Phishing is a cyberattack that uses fake emails, messages, or websites to trick you into providing information or giving an attacker access to your account.

Attackers often pretend to be someone you trust, such as ITS, Microsoft, a professor, supervisor, coworker, or another university department.

A phishing message may ask you to:

  • Verify your account
  • Reset or confirm your password
  • Reactivate or prevent termination of your account
  • Open an attachment
  • Click a link
  • Provide personal information
  • Approve an MFA request

Warning Signs of Phishing

Be cautious when an email:

  • Creates a sense of urgency or fear
  • Asks you to click an unexpected link
  • Requests your password or MFA code
  • Contains an unexpected attachment
  • Comes from an unusual or unfamiliar sender
  • Contains spelling or grammatical errors
  • Uses suspicious links or websites
  • Claims your account will be disabled or terminated unless you act immediately

Remember:

ITS will never ask you to provide your password by email, text message, or an online form.

When in doubt, don't click. Verify first.

 

I Clicked the Link. What Should I Do?

Don't panic. Report it immediately.

If you clicked a phishing link:

If You Entered Your Password

  • Change your university password immediately using the University's official password-management process.
  • Report the incident to ITS.
  • Do not approve unexpected MFA requests.

If You Downloaded or Opened an Attachment

  • Stop interacting with the file.
  • Disconnect from the network if instructed by ITS.
  • Contact ITS immediately and explain what happened.

If You Provided Personal or Financial Information

Contact ITS immediately and explain exactly what information was provided.

The sooner you report an incident, the sooner ITS can help protect your account and the University.