Email and phishing scams

Introduction 

Email is one of the most common ways cybercriminals attempt to steal information, gain access to accounts, or distribute malicious software. These attacks, commonly known as phishing, are designed to deceive recipients into taking actions that compromise their personal information or organizational security.

Phishing emails have become increasingly sophisticated in recent years. Advances in artificial intelligence (AI) and other technologies have made it easier for attackers to create convincing messages that closely resemble legitimate communications from trusted organizations and individuals.

Understanding how phishing attacks work and following a few security best practices can significantly reduce your risk of becoming a victim. This guide explains how to recognize phishing attempts, protect yourself, report suspicious emails, and respond if you believe you've interacted with a malicious message.

If you receive a suspicious email and need assistance reporting it, follow the instructions in the How to Report Spam or Phish article for steps on submitting a phishing report.

 

 

Jump to Section

1. Common Signs of Phishing

2. Best Practices to Protect Your Information 

3. Steps to Take if You Responded to a Phishing Email

4. Additional Resources to Protect Yourself

 

 

Common Signs of Phishing 

Phishing emails don't always look suspicious at first glance. Many are designed to appear as legitimate messages from trusted organizations or individuals. Below are ten of the most common warning signs of phishing emails. While a single indicator does not necessarily mean an email is malicious, recognizing these red flags can help you identify suspicious messages. Select a topic in the table of contents below to jump to more detailed information about each warning sign.

Unexpected or Unsolicited Emails 

Purpose: Phishing emails often begin with messages that the recipient was not expecting. Attackers use unexpected emails to create curiosity, concern, or a sense that action is required.

 

What To Look For: 

  • Emails related to accounts, payments, deliveries, or documents that you were not expecting.

  • Messages asking you to review, approve, or verify something unfamiliar.

  • Notifications about services or accounts you do not use.

  • Emails that appear to come from trusted organizations but have no clear reason for contacting you.

 

Examples: 

  • "Your account requires immediate verification."

  • "You have received a new shared document."

  • "Your package delivery failed."

  • "Invoice attached for your recent purchase."

  • "Your password reset request has been received."

 

Key Takeaway: An unexpected email does not automatically mean it is malicious, but unexpected requests should be carefully reviewed before taking action.

 

Creates a Sense of Urgency 

Purpose: Cybercriminals often try to rush recipients into making quick decisions before they have time to verify whether the message is legitimate.

 

What To Look For: 

  • Threats of account closure or loss of access.

  • Requests requiring immediate action.

  • Messages that create fear, panic, or pressure.

  • Claims that normal procedures can be skipped because of an urgent situation.

 

Examples: 

  • "Your account will be disabled within 24 hours."

  • "Immediate action is required to prevent suspension."

  • "This is your final warning."

  • "Please complete this request before the end of the day."

 

Key Takeaway: Urgency is a common tactic used in phishing. Take time to verify unexpected requests before responding.

 

Requests Sensitive Information 

Purpose: Many phishing attempts are designed to steal personal information, account credentials, or financial details.

 

What To Look For: 

Be cautious of emails requesting

  • Passwords

  • Two-Factor authentication (2FA) access

  • Banking information

  • Credit card numbers

  • Social Security numbers

  • Personal records or confidential documents

 

Examples: 

  • "Reply with your username and password to verify your account."

  • "Provide your 2FA code to complete authentication."

  • "Update your payment information using the attached form."

 

Key Takeaway: Legitimate organizations will not ask you to provide passwords, 2FA access, or sensitive personal information through email.

 

Suspicious Sender Information 

Purpose: Attackers often impersonate trusted individuals or organizations by changing the sender name or using similar-looking email addresses.

 

What To Look For: 

  • Display names that do not match the actual email address.

  • Misspelled or slightly altered domains.

  • Email addresses that use free services (such as Gmail or Hotmail) while claiming to represent an organization.

  • Addresses that look similar to legitimate accounts but contain small changes.

 

Examples: 

  • Legitimate

    • userhelp@uwyo.edu 

  • Suspicious

    • userhelp@gmail.com 

    • userhelp@UW-security.com  

 

Key Takeaway: Do not rely only on the sender name. Always review the actual email address and domain.

 

Suspicious Links or Attachments 

Purpose: Links and attachments are common methods attackers use to steal information, install malware, or gain access to accounts.

 

What To Look For: 

  • Links asking you to sign in or verify an account.

  • Unexpected attachments from known or unknown senders.

  • Files you were not expecting to receive.

  • Links with unusual or misspelled website addresses.

  • Documents requesting you enable macros or additional permissions.

 

Examples: 

  • Fake Microsoft 365 login pages.

  • Unexpected SharePoint or OneDrive file notifications.

  • ZIP files containing unknown documents.

  • Office files asking you to enable content.

 

Key Takeaway: Avoid opening links or attachments unless you were expecting them and can verify they are safe.

 

Unusual Requests  

Purpose: Not all phishing attempts are designed to steal passwords. Some attempt to trick users into completing fraudulent tasks.

 

What To Look For: 

  • Requests involving money, purchases, or account changes.

  • Requests that fall outside your normal responsibilities.

  • Messages pretending to come from supervisors, coworkers, or vendors.

 

Examples: 

  • Requesting gift card purchases.

  • Asking you to change payroll or payment information.

  • Requesting confidential files.

  • Asking you to transfer money.

  • Asking you to purchase equipment or services.

 

Key Takeaway: Unexpected requests involving money, access, or sensitive information should always be verified.

 

Too Good to be True or Emotionally Manipulative 

Purpose: Phishing messages often use strong emotions to influence decisions and encourage recipients to act without thinking.

 

What To Look For: 

Messages designed to create -

  • Excitement

  • Fear

  • Curiosity

  • Sympathy

  • A sense of reward or opportunity

 

Examples: 

  • "You have won a prize."

  • "You are eligible for an exclusive refund."

  • "Help needed immediately due to an emergency."

  • "Claim your limited-time reward."

 

Key Takeaway: Strong emotional reactions can make scams more convincing. Be cautious when a message creates an unusually strong response.

 

Poor Context and Unusual Timing  

Purpose: Even a well-written email may be suspicious if it does not match the situation or your normal interactions.

 

What To Look For: 

  • Requests that do not make sense based on your role or responsibilities.

  • Messages from people who normally communicate differently.

  • Emails received at unusual times or under unusual circumstances.

  • References to events, purchases, or accounts you do not recognize.

 

Examples: 

  • A coworker suddenly requesting sensitive information.

  • A request from a supervisor that differs from their normal communication style.

 

Key Takeaway: Consider whether the email makes sense in context, not just whether it looks professional.

 

Attempt to Bypass Normal Procedures  

Purpose: Attackers often try to convince recipients to ignore standard security processes or approval steps.

 

What To Look For: 

  • Requests to keep information secret.

  • Instructions to avoid contacting others.

  • Requests to use personal email accounts.

  • Pressure to skip normal approvals or verification steps.

 

Examples: 

  • "Please keep this confidential."

  • "I cannot discuss this over the phone, just complete the request."

  • "The normal process is unavailable, so handle this another way."

  • "Do not tell anyone until this is complete."

 

Key Takeaway: Requests to bypass established procedures are a common warning sign of fraud and is heavily avoided by our IT team as a whole.

 

AI-Generated Content 

Purpose: Modern attackers use artificial intelligence and publicly available information to create convincing, personalized phishing emails.

 

What To Look For: 

  • Messages with professional grammar and formatting.

  • Emails personalized with your name, job title, or organization details.

  • Messages that imitate the writing style of someone you know.

  • Highly realistic branding or business communications.

 

Examples: 

  • An email that appears to come from a coworker using their usual writing style that you were not expecting to receive.

  • A fake business request containing accurate information about your organization.

  • A professionally written phishing message without obvious spelling mistakes.

 

Key Takeaway: Grammar, spelling, and professional appearance are no longer reliable ways to identify phishing. Evaluate the request, context, and sender carefully.

 

Jump back to Top of Page

 

Best Practices to Protect Your Information

Recognizing the signs of a phishing email is only the first step. Knowing how to respond can help protect your personal information, University data, and your accounts from compromise. The following best practices outline recommended actions to take, and common mistakes to avoid when you receive a suspicious email.

 

Jump to Section 

1. Recommended Security Practices 

2. Practices to Avoid 

 

Recommended Security Practices 

Following these best practices can help reduce your risk of falling victim to phishing attacks and other email-based threats. Select a topic below to learn more about each recommended security practice.

Verify Before You Trust  

Before responding to an unexpected email, confirm that the request is legitimate.

 

What You Should Do: 

  • Verify requests involving account access, payments, sensitive information, or file sharing.

  • Contact the person or organization using a trusted phone number, website, or separate communication method.

  • Avoid using links or contact information provided in suspicious emails.

 

Remember: When in doubt, verify the request before taking action.

 

Protect Sensitive Information   

Protect your personal information and University data by only sharing sensitive information through approved methods.

 

What You Should Do: 

  • Never share passwords, 2FA access, financial information, or confidential data through email.

  • Use approved secure systems when sharing sensitive information.

  • Verify requests before providing personal or organizational information.

 

Remember: Legitimate organizations will not ask you to provide passwords ever or share security access through email. 

 

Keep Your Device Secure 

Maintaining secure devices helps reduce the risk of malicious files, websites, and other threats.

 

What You Should Do: 

  • Keep your operating system, applications, and browsers updated.

  • Enable automatic updates whenever possible.

  • Keep antivirus and built-in security protections enabled.

  • Do not disable security warnings to open unknown files or websites.

 

Remember: Security updates help protect your device from newly discovered threats.

 

Report Suspicious Emails   

Reporting suspicious emails helps protect yourself, your organization, and other users from future phishing attempts. Security teams use reported messages to identify emerging threats, improve protections, and prevent similar attacks from reaching others.

If you receive a suspicious email, follow the steps in How to Report Spam or Phish Article to learn how to report any phishing attempts.

 

Remember: Reporting suspicious emails helps stop threats before they can impact more users.

 

Monitor Your Account   

Quick action can reduce the impact of a compromised account.

 

What You Should Do: 

  • Review accounts for unusual activity.

  • Change passwords if you entered information into a suspicious website.

  • Report suspected account compromise to the appropriate support team.

  • Watch for unexpected log-in attempts or account changes.

 

Remember: Early reporting can help prevent further damage.

 

Use Approved File Sharing and Collaboration Tools  

Approved collaboration tools provide safer ways to share information than email attachments.

 

What You Should Do: 

  • Use tools such as Microsoft OneDrive or SharePoint for document sharing.

  • Manage file permissions carefully.

  • Avoid sending sensitive documents as email attachments when possible.

 

Remember: Secure sharing tools provide better control over who can access your information.

 

 

Jump back to Top of Page

 

Practices to Avoid  

Knowing what actions to avoid is just as important as knowing what steps to take. The following practices can help reduce the risk of falling victim to phishing attacks and other email-based threats. Select a topic in the table of contents below to jump to more detailed information about each practice.

Links in emails can be useful and are often part of legitimate communication, but they can also be used to direct users to fraudulent websites designed to steal information.

 

Avoid: 

  • Clicking links in unexpected emails without confirming they are legitimate.

  • Entering account credentials or any type of sensitive information after following a suspicious link.

  • Assuming a link is safe because the email appears to come from a trusted organization.

 

Remember: Legitimate emails may contain links, but unexpected requests to log in, verify an account, or provide information should always be reviewed carefully before clicking.

 

Don't Open Unexpected Attachments  

Attachments can be used to deliver malware, malicious software, or files designed to steal information. Even attachments that appear to come from a familiar sender can be dangerous if the sender's account has been compromised.

 

Avoid: 

  • Opening attachments you were not expecting.

  • Opening files from unknown senders or suspicious messages.

  • Enabling additional features, macros, or permissions on documents unless you know the file is safe.

  • Downloading files simply because an email creates a sense of urgency.

 

Remember: A familiar sender does not always mean an attachment is safe. Verify unexpected files before opening them.

 

Don't Reply to Suspicious Emails 

Responding to suspicious emails can confirm that your email address is active and may encourage attackers to send additional messages. Replies can also expose additional information or continue an interaction with a scammer.

 

Avoid: 

  • Replying to suspicious messages to ask if they are legitimate.

  • Providing information requested in a suspicious email.

  • Responding to phishing attempts, even if the message appears to come from a trusted person or organization.

  • Attempting to unsubscribe from messages that appear to be spam or phishing.

 

Remember: Do not engage with suspicious senders. Report the message through the appropriate process instead.

 

Don't Share Sensitive Information to Unexpected Requests  

Email is not always a secure method for exchanging confidential information. Attackers often attempt to collect sensitive information by impersonating trusted individuals or organizations.

 

Avoid: 

  • Sending passwords, 2FA access, or account credentials through email.

  • Sharing financial information or personal data in response to an unexpected request.

  • Providing confidential University or business information without verifying the request.

  • Assuming a request is legitimate because it appears to come from someone you know.

 

Remember: Sensitive information should only be shared through approved and secure methods.

 

Don't Let Urgency Influence Your Decisions 

Phishing attempts often create pressure by making requests appear time-sensitive or urgent. This can cause people to act quickly without taking time to verify the request.

 

Avoid: 

  • Making immediate decisions because an email claims action is required.

  • Ignoring normal procedures because a request appears urgent.

  • Allowing fear, pressure, or excitement to influence your response.

  • Assuming a deadline or threat is legitimate without verification

 

Remember: Urgency is a common tactic used in phishing. Take time to evaluate unexpected requests before acting.

 

Don't Use Contact Information Provided in Suspicious Emails 

Attackers may include fake phone numbers, email addresses, or links to make fraudulent messages appear legitimate. Using the information provided in a suspicious email could connect you directly with the attacker.

 

Avoid: 

  • Calling phone numbers listed in suspicious emails.

  • Replying to the sender to confirm whether the message is legitimate.

  • Using links provided in suspicious messages to verify an account or request.

  • Trusting contact information that cannot be independently confirmed.

 

 

Remember: If you need to verify a request, use contact information from a trusted source rather than information provided in the email.

 

 

Jump back to Top of Page

 

 

Steps to Take if You Responded to a Phishing Attempt 

If you have interacted with a suspicious email, taking action quickly can help reduce the potential impact and protect your accounts and information. Select a topic below to learn more about the steps to take after responding to a phishing attempt.

 

Stop Any Further Interaction 

If you clicked a link, opened an attachment, or replied to a suspicious email, stop interacting with the message immediately.

 

What To Do: 

  • Close the webpage or document.

  • Do not provide additional information.

  • Do not continue communicating with the sender.

  • Do not open any additional attachments or links from the message.

 

Remember: Continuing to interact with a phishing email may provide attackers with additional opportunities to compromise your information.

 

Change Your Passwords If You Entered Credentials 

If you entered your username, password, or other login information into a suspicious website, change your password as soon as possible.

 

What To Do: 

  • Change the password for the affected account.

  • Change the password anywhere else you reused the same credentials.

  • Do not wait to see if suspicious activity occurs.

 

Remember: Changing exposed passwords quickly can help prevent unauthorized account access.

 

Report the Phishing Attempt  

Reporting suspicious emails helps protect yourself, your organization, and other users from future phishing attempts. Security teams use reported messages to identify emerging threats, improve protections, and prevent similar attacks from reaching others.

 

What To Do: 

  • Download originally email with all interaction as a .eml file

  • Contact IT support if you entered account credentials or sensitive information at 307-766-4357, option 1 or through email at userhelp@uwyo.edu 

    • Please note if you are emailing the UWIT Help Desk, to always attach the .eml file 

  • Provide details about what information was shared or what actions were taken.

 

Remember: Reporting helps security teams respond quickly and reduce the impact of phishing attempts.

 

Secure Your Account  

If your University account has been compromised, the Information Security team will investigate the incident and take appropriate action to help secure your account. Depending on the circumstances, your account may be temporarily disabled or your password may be reset to prevent unauthorized access while the incident is being investigated.

 

What To Expect: 

  • The Information Security team will review the reported activity.

  • A compromised account support ticket may be created on your behalf.

  • Your account may be temporarily disabled or your password may be reset until it can be secured.

  • You may be required to complete cybersecurity awareness training or customer education before access to your account is restored.

 

If you shared passwords or other credentials for non-University accounts (such as personal email, banking, shopping, or social media accounts), the University cannot secure those accounts on your behalf. You should immediately contact the appropriate organization, change your password, and follow any additional security recommendations they provide. If you shared banking or credit card information, contact your financial institution as soon as possible to report the incident and discuss steps to protect your account.

 

Remember: The Information Security team can assist with University-managed accounts, but you are responsible for securing any personal accounts that may have been affected. These measures are designed to protect your account, University data, and other users while the incident is resolved.

 

Monitor for Suspicious Activity   

Continue monitoring your accounts after interacting with a phishing attempt.

 

What To Do: 

  • Review financial accounts for unauthorized transactions.

  • Watch for unusual emails, password resets, 2FA access, or account notifications.

  • Be cautious of follow-up phishing attempts.

 

Remember: Attackers may use information collected from one phishing attempt in future scams.

 

If You Downloaded or Opened a File   

If you opened an attachment or downloaded a file from a suspicious email, additional action may be needed.

 

What To Do: 

  • Disconnect from the network if you believe malware may have been installed.

  • Run a security scan using approved antivirus tools.

    • Personal Devices: You may use your trusted antivirus software (EX: Windows Security, MalewareBytes, etc...) 

    • UW Owned Devices: Please use the Windows Security/Defender or MalewareBytes to run scan on device  

  • If you are still concerned after taking these steps, please contact the UWIT Help Desk at 307-766-4357, option 1, for further assistance.

 

Remember: Malicious files may continue affecting your device even after the email is deleted.

 

 

Jump back to Top of Page

 

Additional Resources to Protect Yourself 

If a phishing attack involved your personal information or accounts outside of the University of Wyoming, additional steps may be necessary to protect your identity and financial information. While UW Information Security can assist with University-managed accounts, you are responsible for securing personal accounts and working with the appropriate organizations if your personal information was compromised.

 

Jump to Section

1. Report Spam or Fraud to the Federal Trade Commission (FTC) 

2. Monitor Your Credit 

3. Contact Your Financial Institution  

4. Report Identity Theft  

5. Report Tax-Related Identity Theft 

 

Report Spam or Fraud to the Federal Trade Commission (FTC) 

If you received a phishing email, scam, or other fraudulent message, report it to the Federal Trade Commission (FTC). Reports help identify emerging scams and support investigations into fraudulent activity.

 

The FTC Provides Resources To:

  • Report phishing emails and online scams.

  • Report identity theft.

  • Receive personalized recovery recommendations.

 

Resource: 

 

Monitor Your Credit  

If you shared your Social Security number or other sensitive personal information, consider taking steps to protect your credit.

 

Recommended Actions:

  • Place a free 90-day fraud alert with one of the three major credit bureaus.

    • The credit bureau you contact will notify the other two on your behalf.

    • A fraud alert requires businesses to verify your identity before opening new credit accounts in your name.

  • Obtain and review your credit reports for unfamiliar accounts or suspicious activity.

  • Continue monitoring your credit for signs of identity theft.

 

Resources: 

  • Equifax - Provides fraud alerts, credit freezes, and credit monitoring services to help protect against identity theft.

  • Experian - Offers fraud alerts, credit freezes, and identity protection services. They also provide tools to help monitor your credit and identify suspicious activity that may indicate identity theft.

  • TransUnion - Allows consumers to place fraud alerts and credit freezes while providing resources to help identify and respond to potential identity theft. They also offer credit monitoring and fraud prevention services.

 

Contact Your Financial Institution   

If you shared banking information, debit card information, or credit card information, contact your financial institution immediately.

 

Your Financial Institution May Recommend:

  • Monitoring your account for fraudulent activity.

  • Freezing or replacing affected debit or credit cards.

  • Disputing unauthorized transactions.

  • Placing additional security measures on your account.

 

Remember: The sooner you report the incident, the greater the chance of preventing or minimizing financial loss.

 

Report Identity Theft   

If you believe your personal information has been used without your permission, additional steps may be needed to recover from identity theft. The Federal Trade Commission (FTC) provides resources to help individuals create a recovery plan, document the incident, and take steps to restore their identity.

 

What To Do:

  • Report identity theft to the FTC.

  • Create an Identity Theft Report and personalized recovery plan.

  • Receive guidance based on the type of identity theft you experienced.

  • Access recovery resources, forms, and letters to help resolve fraudulent activity.

 

Resource: 

  • IdentityTheft.gov - Provides step-by-step guidance for recovering from identity theft and creating a personalized recovery plan.

 

Report Tax-Related Identity Theft   

If you believe someone has used your personal information for employment or tax-related fraud, additional steps may be required to protect your identity and resolve the issue. The Internal Revenue Service (IRS) provides guidance for reporting suspected tax-related identity theft and responding to fraudulent activity.

 

What To Do:

  • Report suspected tax-related identity theft.

  • Complete IRS Form 14039 - Identity Theft Affidavit when applicable.

  • Understand the steps needed to resolve tax-related identity theft.

  • Respond to notices regarding fraudulent tax activity or unknown employers reporting income under your identity.

 

Resources: 

  • irs.gov - Provides information on reporting and resolving tax-related identity theft, including resources for individuals whose personal information has been misused.

 

 

Jump back to Top of Page

Was this helpful?
0 reviews