Email and Phishing Scams

Introduction 

Email is one of the most common ways cybercriminals attempt to steal information, gain access to accounts, or distribute malicious software. These attacks, commonly known as phishing, are designed to deceive recipients into taking actions that compromise their personal information or organizational security.

Phishing emails have become increasingly sophisticated in recent years. Advances in artificial intelligence (AI) and other technologies have made it easier for attackers to create convincing messages that closely resemble legitimate communications from trusted organizations and individuals.

Understanding how phishing attacks work and following a few security best practices can significantly reduce your risk of becoming a victim. This guide explains what phishing is, how to recognize phishing attempts, protect yourself, report suspicious emails, and respond if you believe you've interacted with a malicious message.

If you receive a suspicious email and need assistance reporting it, follow the instructions in the How to Report Spam or Phish article for steps on submitting a phishing report.

 

Jump to Section

1. What is Phishing and How Does it Happen at the University?

2. Common Signs of Phishing

3. Best Practices to Protect Your Information 

4. Steps to Take if You Responded to a Phishing Email

5. Additional Resources to Protect Yourself

 

 

What is Phishing and How Does it Happen at the University?

Phishing is a type of cyberattack in which someone impersonates a trusted person, organization, or service to trick you into providing sensitive information or taking an action that could compromise your account or device. Attackers may try to obtain information such as usernames, passwords, financial information, or other personal data.

Phishing most commonly occurs through email and text messages, but it can also happen through phone calls, social media, messaging apps, websites, and other online platforms. Phishing messages are often designed to look legitimate and may use familiar logos, names, or language to create a sense of urgency or trust.

 

How Does Phishing Happen at University of Wyoming?

At the University of Wyoming, one common form of phishing involves messages that appear to come from UWIT or another university department. These messages may claim that there is a problem with your account, warn that your account will be deactivated, or ask you to verify your information by clicking a link and entering your UW username and password.

UWIT will never ask for your UW account password. If a message asks you to provide your password or directs you to a link where you are asked to enter it, treat the message as suspicious, regardless of how legitimate it looks or who it appears to come from.

UWIT may send legitimate account-related notifications, but you should always be cautious with unexpected messages that ask you to click a link, provide information, or approve access.

 

 

Common Signs of Phishing 

Phishing emails don't always look suspicious at first glance. Many are designed to appear as legitimate messages from trusted organizations or individuals. Below are ten of the most common warning signs of phishing emails. While a single indicator does not necessarily mean an email is malicious, recognizing these red flags can help you identify suspicious messages. Select a topic below to learn more detailed information about each warning sign.

Purpose: Phishing emails often begin with messages that the recipient was not expecting. Attackers use unexpected emails to create curiosity, concern, or a sense that action is required.

 

What To Look For: 

  • Emails related to accounts, payments, deliveries, or documents that you were not expecting.

  • Messages asking you to review, approve, or verify something unfamiliar.

  • Notifications about services or accounts you do not use.

  • Emails that appear to come from trusted organizations but have no clear reason for contacting you.

 

Examples: 

  • "Your account requires immediate verification."

  • "You have received a new shared document."

  • "Your package delivery failed."

  • "Invoice attached for your recent purchase."

  • "Your password reset request has been received."

 

Key Takeaway: An unexpected email does not automatically mean it is malicious, but unexpected requests should be carefully reviewed before taking action.

Purpose: Cybercriminals often try to rush recipients into making quick decisions before they have time to verify whether the message is legitimate.

 

What To Look For: 

  • Threats of account closure or loss of access.

  • Requests requiring immediate action.

  • Messages that create fear, panic, or pressure.

  • Claims that normal procedures can be skipped because of an urgent situation.

 

Examples: 

  • "Your account will be disabled within 24 hours."

  • "Immediate action is required to prevent suspension."

  • "This is your final warning."

  • "Please complete this request before the end of the day."

 

Key Takeaway: Urgency is a common tactic used in phishing. Take time to verify unexpected requests before responding.

Purpose: Many phishing attempts are designed to steal personal information, account credentials, or financial details.

 

What To Look For: 

Be cautious of emails requesting

  • Passwords

  • Two-Factor authentication (2FA) access

  • Banking information

  • Credit card numbers

  • Social Security numbers

  • Personal records or confidential documents

 

Examples: 

  • "Reply with your username and password to verify your account."

  • "Provide your 2FA code to complete authentication."

  • "Update your payment information using the attached form."

 

Key Takeaway: Legitimate organizations will not ask you to provide passwords, 2FA access, or sensitive personal information through email.

Purpose: Attackers often impersonate trusted individuals or organizations by changing the sender name or using similar-looking email addresses.

 

What To Look For: 

  • Display names that do not match the actual email address.

  • Misspelled or slightly altered domains.

  • Email addresses that use free services (such as Gmail or Hotmail) while claiming to represent an organization.

  • Addresses that look similar to legitimate accounts but contain small changes.

  • Ensure you are viewing the full email address and not just the contact name

 

Examples: 

  • Legitimate

    • userhelp@uwyo.edu 

  • Suspicious

    • userhelp@gmail.com 

    • userhelp@UW-security.com  

 

Key Takeaway: Do not rely only on the sender name. Always review the actual email address and domain.

Purpose: Links and attachments are common methods attackers use to steal information, install malware, or gain access to accounts.

 

What To Look For: 

  • Links asking you to sign in or verify an account.

  • Unexpected attachments from known or unknown senders.

  • Files you were not expecting to receive.

  • Links with unusual or misspelled website addresses.

  • Documents requesting you enable macros or additional permissions.

 

Examples: 

  • Fake Microsoft 365 login pages.

  • Unexpected SharePoint or OneDrive file notifications.

  • ZIP files containing unknown documents.

  • Office files asking you to enable content.

 

Key Takeaway: Avoid opening links or attachments unless you were expecting them and can verify they are safe.

Purpose: Not all phishing attempts are designed to steal passwords. Some attempt to trick users into completing fraudulent tasks.

 

What To Look For: 

  • Requests involving money, purchases, or account changes.

  • Requests that fall outside your normal responsibilities.

  • Messages pretending to come from supervisors, coworkers, or vendors.

 

Examples: 

  • Requesting gift card purchases.

  • Asking you to change payroll or payment information.

  • Requesting confidential files.

  • Asking you to transfer money.

  • Asking you to purchase equipment or services.

 

Key Takeaway: Unexpected requests involving money, access, or sensitive information should always be verified.

Purpose: Phishing messages often use strong emotions to influence decisions and encourage recipients to act without thinking.

 

What To Look For: 

Messages designed to create -

  • Excitement

  • Fear

  • Curiosity

  • Sympathy

  • A sense of reward or opportunity

 

Examples: 

  • "You have won a prize."

  • "You are eligible for an exclusive refund."

  • "Help needed immediately due to an emergency."

  • "Claim your limited-time reward."

 

Key Takeaway: Strong emotional reactions can make scams more convincing. Be cautious when a message creates an unusually strong response.

Purpose: Even a well-written email may be suspicious if it does not match the situation or your normal interactions.

 

What To Look For: 

  • Requests that do not make sense based on your role or responsibilities.

  • Messages from people who normally communicate differently.

  • Emails received at unusual times or under unusual circumstances.

  • References to events, purchases, or accounts you do not recognize.

 

Examples: 

  • A coworker suddenly requesting sensitive information.

  • A request from a supervisor that differs from their normal communication style.

 

Key Takeaway: Consider whether the email makes sense in context, not just whether it looks professional.

Purpose: Attackers often try to convince recipients to ignore standard security processes or approval steps.

 

What To Look For: 

  • Requests to keep information secret.

  • Instructions to avoid contacting others.

  • Requests to use personal email accounts.

  • Pressure to skip normal approvals or verification steps.

  • Sending Requests through a text message claiming to be UW IT.

 

NOTE: UWIT only uses SMS (text messages) when assisting clients with the initial setup of Duo Mobile. Outside of this process, UWIT will never send you a text message regarding your account or asking you to provide or approve access. If you receive a text claiming to be from UWIT that requests account information or access, do NOT respond or interact with the message

 

Examples: 

  • "Please keep this confidential."

  • "I cannot discuss this over the phone, just complete the request."

  • "The normal process is unavailable, so handle this another way."

  • "Do not tell anyone until this is complete."

 

Key Takeaway: Requests to bypass established procedures are a common warning sign of fraud and is heavily avoided by our IT team as a whole.

Purpose: Modern attackers use artificial intelligence and publicly available information to create convincing, personalized phishing emails.

 

What To Look For: 

  • Messages with professional grammar and formatting.

  • Emails personalized with your name, job title, or organization details.

  • Messages that imitate the writing style of someone you know.

  • Highly realistic branding or business communications.

 

Examples: 

  • An email that appears to come from a coworker using their usual writing style that you were not expecting to receive.

  • A fake business request containing accurate information about your organization.

  • A professionally written phishing message without obvious spelling mistakes.

 

Key Takeaway: Grammar, spelling, and professional appearance are no longer reliable ways to identify phishing. Evaluate the request, context, and sender carefully.

Jump back to Top of Page

 

 

Best Practices to Protect Your Information

Recognizing the signs of a phishing email is only the first step. Knowing how to respond can help protect your personal information, University data, and your accounts from compromise. The following best practices outline recommended actions to take, and common mistakes to avoid when you receive a suspicious email.

 

Jump to Section 

1. Recommended Security Practices 

2. Practices to Avoid 

 

Recommended Security Practices 

Following these best practices can help reduce your risk of falling victim to phishing attacks and other email-based threats. Select a topic below to learn more about each recommended security practice.

Before responding to an unexpected email, confirm that the request is legitimate.

 

What You Should Do: 

  • Verify requests involving account access, payments, sensitive information, or file sharing.

  • Contact the person or organization using a trusted phone number, website, or separate communication method.

  • Avoid using links or contact information provided in suspicious emails.

 

Remember: When in doubt, verify the request before taking action.

Protect your personal information and University data by only sharing sensitive information through approved methods.

 

What You Should Do: 

  • Never share passwords, 2FA access, financial information, or confidential data through email or text.

  • Use approved secure systems when sharing sensitive information.

  • Verify requests before providing personal or organizational information.

 

Remember: Legitimate organizations will not ask you to provide passwords ever or share security access through email. 

Maintaining secure devices helps reduce the risk of malicious files, websites, and other threats.

 

What You Should Do: 

  • Keep your operating system, applications, and browsers updated.

  • Enable automatic updates whenever possible.

  • Keep antivirus and built-in security protections enabled.

  • Do not disable security warnings to open unknown files or websites.

 

Remember: Security updates help protect your device from newly discovered threats.

Reporting suspicious emails helps protect yourself, your organization, and other users from future phishing attempts. Security teams use reported messages to identify emerging threats, improve protections, and prevent similar attacks from reaching others.

If you receive a suspicious email, follow the steps in How to Report Spam or Phish Article to learn how to report any phishing attempts.

 

Remember: Reporting suspicious emails helps stop threats before they can impact more users.

Quick action can reduce the impact of a compromised account.

 

What You Should Do: 

  • Review accounts for unusual activity.

  • Change passwords if you entered information into a suspicious website.

  • Report suspected account compromise to the appropriate support team.

  • Watch for unexpected log-in attempts or account changes.

 

Remember: Early reporting can help prevent further damage.

Approved collaboration tools provide safer ways to share information than email attachments.

 

What You Should Do: 

  • Use tools such as Microsoft OneDrive or SharePoint for document sharing.

  • Manage file permissions carefully.

  • Avoid sending sensitive documents as email attachments.

 

Remember: Secure sharing tools provide better control over who can access your information.

Jump back to Top of Page

 

 

Practices to Avoid  

Knowing what actions to avoid is just as important as knowing what steps to take. The following practices can help reduce the risk of falling victim to phishing attacks and other email-based threats. Select a topic below to learn more detailed information about each practice.

 

Links in emails can be useful and are often part of legitimate communication, but they can also be used to direct users to fraudulent websites designed to steal information.

 

Avoid: 

  • Clicking links in unexpected emails without confirming they are legitimate.

  • Entering account credentials or any type of sensitive information after following a suspicious link.

  • Assuming a link is safe because the email appears to come from a trusted organization.

 

Remember: Legitimate emails may contain links, but unexpected requests to log in, verify an account, or provide information should always be reviewed carefully before clicking.

Attachments can be used to deliver malware, malicious software, or files designed to steal information. Even attachments that appear to come from a familiar sender can be dangerous if the sender's account has been compromised.

 

Avoid: 

  • Opening attachments you were not expecting.

  • Opening files from unknown senders or suspicious messages.

  • Enabling additional features, macros, or permissions on documents unless you know the file is safe.

  • Downloading files simply because an email creates a sense of urgency.

 

Remember: A familiar sender does not always mean an attachment is safe. Verify unexpected files before opening them.

Responding to suspicious emails can confirm that your email address is active and may encourage attackers to send additional messages. Replies can also expose additional information or continue an interaction with a scammer.

 

Avoid: 

  • Replying to suspicious messages to ask if they are legitimate.

  • Providing information requested in a suspicious email.

  • Responding to phishing attempts, even if the message appears to come from a trusted person or organization.

  • Attempting to unsubscribe from messages that appear to be spam or phishing.

 

Remember: Do not engage with suspicious senders. Report the message through the appropriate process instead.

Email is not always a secure method for exchanging confidential information. Attackers often attempt to collect sensitive information by impersonating trusted individuals or organizations.

 

Avoid: 

  • Sending passwords, 2FA access, or account credentials through email.

  • Sharing financial information or personal data in response to an unexpected request.

  • Providing confidential University or business information without verifying the request.

  • Assuming a request is legitimate because it appears to come from someone you know.

 

Remember: Sensitive information should only be shared through approved and secure methods.

Phishing attempts often create pressure by making requests appear time-sensitive or urgent. This can cause people to act quickly without taking time to verify the request.

 

Avoid: 

  • Making immediate decisions because an email claims action is required.

  • Ignoring normal procedures because a request appears urgent.

  • Allowing fear, pressure, or excitement to influence your response.

  • Assuming a deadline or threat is legitimate without verification

 

Remember: Urgency is a common tactic used in phishing. Take time to evaluate unexpected requests before acting.

Attackers may include fake phone numbers, email addresses, or links to make fraudulent messages appear legitimate. Using the information provided in a suspicious email could connect you directly with the attacker.

 

Avoid: 

  • Calling phone numbers listed in suspicious emails.

  • Replying to the sender to confirm whether the message is legitimate.

  • Using links provided in suspicious messages to verify an account or request.

  • Trusting contact information that cannot be independently confirmed.

 

 

Remember: If you need to verify a request, use contact information from a trusted source rather than information provided in the email.

Jump back to Top of Page

 

 

Steps to Take if You Responded to a Phishing Attempt 

If you have interacted with a suspicious email, taking action quickly can help reduce the potential impact and protect your accounts and information. Select a topic below to learn more about the steps to take after responding to a phishing attempt.

 

If you clicked a link, opened an attachment, or replied to a suspicious email, stop interacting with the message immediately.

 

What To Do: 

  • Close the webpage or document.

  • Do not provide additional information.

  • Do not continue communicating with the sender.

  • Do not open any additional attachments or links from the message.

 

Remember: Continuing to interact with a phishing email may provide attackers with additional opportunities to compromise your information.

If you entered your username, password, or other login information into a suspicious website, change your password as soon as possible.

 

What To Do: 

  • Change the password for the affected account.

  • Change the password anywhere else you reused the same credentials.

  • Do not wait to see if suspicious activity occurs.

 

Remember: Changing exposed passwords quickly can help prevent unauthorized account access.

Reporting suspicious emails helps protect yourself, your organization, and other users from future phishing attempts. Security teams use reported messages to identify emerging threats, improve protections, and prevent similar attacks from reaching others.

 

What To Do: 

  • Download originally email with all interaction as a .eml file

  • Contact IT support if you entered account credentials or sensitive information at 307-766-4357, option 1 or through email at userhelp@uwyo.edu 

    • Please note if you are emailing the UWIT Help Desk, to always attach the .eml file 

  • Provide details about what information was shared or what actions were taken.

 

Remember: Reporting helps security teams respond quickly and reduce the impact of phishing attempts.

If your University account has been compromised, the Information Security team will investigate the incident and take appropriate action to help secure your account. Depending on the circumstances, your account may be temporarily disabled or your password may be reset to prevent unauthorized access while the incident is being investigated.

 

What To Expect: 

  • The Information Security team will review the reported activity.

  • A compromised account support ticket may be created on your behalf.

  • Your account may be temporarily disabled or your password may be reset until it can be secured.

  • You may be required to complete cybersecurity awareness training or customer education before access to your account is restored.

 

If you shared passwords or other credentials for non-University accounts (such as personal email, banking, shopping, or social media accounts), the University cannot secure those accounts on your behalf. You should immediately contact the appropriate organization, change your password, and follow any additional security recommendations they provide. If you shared banking or credit card information, contact your financial institution as soon as possible to report the incident and discuss steps to protect your account.

 

Remember: The Information Security team can assist with University-managed accounts, but you are responsible for securing any personal accounts that may have been affected. These measures are designed to protect your account, University data, and other users while the incident is resolved.

Continue monitoring your accounts after interacting with a phishing attempt.

 

What To Do: 

  • Review financial accounts for unauthorized transactions.

  • Watch for unusual emails, password resets, 2FA access, or account notifications.

  • Be cautious of follow-up phishing attempts.

 

Remember: Attackers may use information collected from one phishing attempt in future scams.

If you opened an attachment or downloaded a file from a suspicious email, additional action may be needed.

 

What To Do: 

  • Disconnect from the network if you believe malware may have been installed.

  • Run a security scan using approved antivirus tools.

    • Personal Devices: You may use your trusted antivirus software (EX: Windows Security, MalewareBytes, etc...) 

    • UW Owned Devices: Please use the Windows Security/Defender or MalewareBytes to run scan on device  

  • If you are still concerned after taking these steps, please contact the UWIT Help Desk at 307-766-4357, option 1, for further assistance.

 

Remember: Malicious files may continue affecting your device even after the email is deleted.

If you shared University of Wyoming institutional data or confidential information about others, such as research data or confidential student, faculty, or staff information, additional action may be needed.

 

What To Do: 

  • Report the incident IMMEDIATELY to the Risk Management and Safety Division.

  • Provide as much information as possible about what information was shared, who received it, and how it was shared.

  • If you are unsure whether the information you shared is considered confidential or sensitive, report the incident anyway so it can be properly evaluated.

 

Remember: Reporting an incident as soon as possible can help reduce the potential impact and allow the appropriate UW teams to take steps to protect the information.

Jump back to Top of Page

 

 

Additional Resources to Protect Yourself 

If a phishing attack involved your personal information or accounts outside of the University of Wyoming, additional steps may be necessary to protect your identity and financial information. While UW Information Security can assist with University-managed accounts, you are responsible for securing personal accounts and working with the appropriate organizations if your personal information was compromised.

 

If you received a phishing email, scam, or other fraudulent message, report it to the Federal Trade Commission (FTC). Reports help identify emerging scams and support investigations into fraudulent activity.

 

The FTC Provides Resources To:

  • Report phishing emails and online scams.

  • Report identity theft.

  • Receive personalized recovery recommendations.

 

Resource: 

If you shared your Social Security number or other sensitive personal information, consider taking steps to protect your credit.

 

Recommended Actions:

  • Place a free 90-day fraud alert with one of the three major credit bureaus.

    • The credit bureau you contact will notify the other two on your behalf.

    • A fraud alert requires businesses to verify your identity before opening new credit accounts in your name.

  • Obtain and review your credit reports for unfamiliar accounts or suspicious activity.

  • Continue monitoring your credit for signs of identity theft.

 

Resources: 

  • Equifax - Provides fraud alerts, credit freezes, and credit monitoring services to help protect against identity theft.

  • Experian - Offers fraud alerts, credit freezes, and identity protection services. They also provide tools to help monitor your credit and identify suspicious activity that may indicate identity theft.

  • TransUnion - Allows consumers to place fraud alerts and credit freezes while providing resources to help identify and respond to potential identity theft. They also offer credit monitoring and fraud prevention services.

If you shared banking information, debit card information, or credit card information, contact your financial institution immediately.

 

Your Financial Institution May Recommend:

  • Monitoring your account for fraudulent activity.

  • Freezing or replacing affected debit or credit cards.

  • Disputing unauthorized transactions.

  • Placing additional security measures on your account.

 

Remember: The sooner you report the incident, the greater the chance of preventing or minimizing financial loss.

If you believe your personal information has been used without your permission, additional steps may be needed to recover from identity theft. The Federal Trade Commission (FTC) provides resources to help individuals create a recovery plan, document the incident, and take steps to restore their identity.

 

What To Do:

  • Report identity theft to the FTC.

  • Create an Identity Theft Report and personalized recovery plan.

  • Receive guidance based on the type of identity theft you experienced.

  • Access recovery resources, forms, and letters to help resolve fraudulent activity.

 

Resource: 

  • IdentityTheft.gov - Provides step-by-step guidance for recovering from identity theft and creating a personalized recovery plan.

If you believe someone has used your personal information for employment or tax-related fraud, additional steps may be required to protect your identity and resolve the issue. The Internal Revenue Service (IRS) provides guidance for reporting suspected tax-related identity theft and responding to fraudulent activity.

 

What To Do:

  • Report suspected tax-related identity theft.

  • Complete IRS Form 14039 - Identity Theft Affidavit when applicable.

  • Understand the steps needed to resolve tax-related identity theft.

  • Respond to notices regarding fraudulent tax activity or unknown employers reporting income under your identity.

 

Resources: 

  • irs.gov - Provides information on reporting and resolving tax-related identity theft, including resources for individuals whose personal information has been misused.

Jump back to Top of Page

 

 

Was this helpful?
0 reviews