Phishing is when a criminal pretends to be someone you trust, usually to get your password, your money, or access to university systems. It arrives by email most often, but also by text message, phone call, or messaging app.
It works because it looks ordinary. A message from your bank, a request from a colleague, a delivery you were expecting. The skill is not spotting something obviously fake, it is pausing when something feels slightly off.
How to spot a phishing email
No single sign proves an email is fake. Look for a combination of these:
- Urgency. Your account will be closed today, act now, respond within two hours
- An unexpected request. A payment, a password, a login, a gift card
- The sender address does not match. The display name says the university, the actual address does not
- Generic greeting. Dear User, Dear Customer, Dear Account Holder
- Links that do not go where they claim. Hover over a link before clicking to see the real destination
- Attachments you were not expecting. Especially zip files, invoices, or documents asking you to enable content
What to do if you suspect an email
- Do not click any links or open any attachments
- Do not reply, even to tell them to stop
- Do not forward it to colleagues to ask what they think
- Report it using the form on our Report an Incident page
- Delete it once you have reported it
Already clicked? Do this now
- Change your password immediately, on any account where you entered it
- If you reused that password elsewhere, change it there too
- Report it straight away, even if you think nothing happened
- Watch your accounts for anything you did not do
Speed matters more than embarrassment. The sooner we know, the more we can protect.