Overview
Phishing is a scam that uses a deceptive message to trick you into taking an action that benefits the scammer. A phishing message may try to get you to:
- Enter your username and password on a fake sign-in page.
- Share an MFA code or approve an MFA request.
- Open a harmful attachment.
- Click a link that installs malicious software or takes you to a fraudulent website.
- Send money, gift cards, banking information, personal information, or university data.
Phishing messages often arrive by email, but similar scams can also use text messages, phone calls, social media, or collaboration tools.
A phishing message does not have to contain obvious spelling mistakes or poor formatting. It may use real logos, familiar names, information found online, or an account that has already been compromised.
How It Works
Most phishing attempts follow a simple pattern:
- The message creates a reason to act. It may claim that your account will be closed, a payment failed, a document is waiting, a package cannot be delivered, or someone needs urgent help.
- The message directs you to a link, attachment, phone number, QR code, or reply.
- The scammer collects information or gains access. A fake website may capture your password, an attachment may install malicious software, or a reply may begin a longer financial or identity scam.
Phishing messages frequently impersonate organizations or people you already know, including:
- A UM office, instructor, supervisor, coworker, or student.
- Microsoft or another technology provider.
- A bank, delivery company, government agency, or online retailer.
- A vendor or business partner.
Warning Signs
Be cautious when a message includes one or more of the following:
- An unexpected request to sign in, open a document, review a shared file, or confirm account information.
- Pressure to act immediately or a threat that an account, payment, job, registration, or service will be affected.
- A sender address that does not match the displayed name or organization.
- A link whose destination does not match the text shown in the message.
- An unexpected attachment, especially one asking you to enable content, run a file, or sign in before viewing it.
- A request for a password, MFA code, Social Security number, banking information, gift cards, cryptocurrency, or other payment.
- A request to keep the matter secret or avoid normal university or business processes.
- A sign-in page reached through an unexpected message rather than through a website or application you opened yourself.
- A message that seems unusual for the sender, even if it comes from a real account.
No single sign proves that a message is fraudulent. Consider the full context and verify unusual requests through a separate, trusted method.
How to Protect Yourself
- Pause before acting. Urgency is often used to prevent careful review.
- Verify the request independently. Contact the person or organization using a phone number, website, directory entry, or application you already trust. Do not use the contact information provided in the suspicious message.
- Go directly to the service. Open the official application or type the known website address instead of following a sign-in link from an unexpected message.
- Check the full sender address. A familiar display name is not enough.
- Preview links before opening them. On a computer, place the pointer over the link to view its destination. On a mobile device, use caution with links that are shortened or difficult to inspect.
- Do not open unexpected attachments. Confirm the file with the sender through another method first.
- Never provide passwords or MFA codes in response to a message.
- Use MFA and a unique password for each important account. A password manager can help create and store strong passwords.
- Do not reply to the suspicious message to ask whether it is real. If the sender's account is compromised, the attacker may answer.
What You Should Do at UM
If you receive a suspected phishing message in your UM email account:
- Do not click links, open attachments, reply, or call a number in the message.
- Use Outlook's Report Message tool and report the message as phishing.
- Delete the message after reporting it. Outlook's Report Message tool may remove the message automatically. If the message is no longer in your mailbox, no additional deletion is needed.
If the Report Message tool is unavailable, or if the message involves a sensitive or unusual UM process, contact the UM IT Helpdesk or UM Information Security Office using an approved UM contact method.
If you interacted with the message:
- Entered your UM password: Change it immediately through the normal UM account-management process and contact the UM IT Helpdesk or UM Information Security Office.
- Shared an MFA code or approved an unexpected prompt: Deny any further requests and contact UM support immediately.
- Opened an attachment, installed software, or allowed a download: Stop interacting with the message and contact UM support for device guidance.
- Sent university data, personal information, or money: Contact the UM Information Security Office and the appropriate UM office through a trusted contact method. If banking or card information was involved, contact the financial institution as well.
Simply receiving or viewing a phishing message does not mean your account or device has been compromised. Report it, delete it, and take additional action only if you interacted with it or UM support directs you to do so.
Additional Questions
For a message involving a UM account, UM device, university data, or a UM financial or business process, contact the UM IT Helpdesk and the UM Information Security Office.
For phishing in a personal email account, use the email provider's official phishing-reporting and account-recovery tools.
If you disclosed banking or card information, sent money, or notice unauthorized transactions, contact the financial institution immediately using a trusted number or website. General consumer scam reports can be submitted to the Federal Trade Commission through its official reporting service.
Additional Resources