Overview
A scam is a deceptive attempt to obtain money, personal information, account access, or another benefit. Scammers may contact you by email, text message, phone, social media, postal mail, online advertisement, website, or in person.
Scams change frequently, but the underlying methods are consistent. The scammer creates a believable identity or story, produces an emotional reaction, and directs you to act before you can verify the request.
No single spelling error, logo, caller ID, web address, or communication method determines whether something is a scam. Review the full situation and verify unusual requests through a separate source you already trust.
How It Works
Many scams follow this pattern:
- The scammer impersonates a person or organization. The contact may appear to come from a government agency, bank, retailer, employer, university office, technology company, family member, or other trusted source.
- The scammer presents a problem, opportunity, or relationship. Common stories involve an account problem, debt, refund, prize, job, investment, purchase, family emergency, romance, or legal threat.
- The scammer creates pressure. You may be told to act immediately, remain on the phone, keep the matter secret, or avoid contacting anyone else.
- The scammer requests an action. This may involve sending money, buying gift cards, moving funds, sharing personal information, entering a password, approving MFA, opening a file, installing software, or allowing remote access.
- The scammer attempts to prevent recovery. The payment method may be difficult to reverse, the contact account may disappear, or the scammer may return with another request or a false offer to recover the loss.
Scammers can use compromised accounts, copied websites, artificial intelligence, altered images, and publicly available information. A message can come from a real account and still be fraudulent if the account has been compromised.
Warning Signs
Be cautious when a person or message:
- Contacts you unexpectedly and asks for money, account access, or sensitive information.
- Claims to represent a familiar organization but wants you to use a link, phone number, or account provided only in the message.
- Creates urgency, fear, excitement, sympathy, or romantic trust to discourage careful review.
- Threatens arrest, legal action, account closure, loss of employment, loss of benefits, or another immediate consequence.
- Says you won a prize but must pay a fee, tax, shipping charge, or deposit to receive it.
- Guarantees an investment return or claims there is little or no risk.
- Requires payment by gift card, cryptocurrency, wire transfer, cash, gold, or another unusual method.
- Instructs you to move money to a “safe” account or lie to a financial institution about the reason for a transaction.
- Asks for a password, MFA code, PIN, Social Security number, bank information, identity document, or remote access to a device.
- Tells you to keep the request secret or not to contact a supervisor, family member, bank, government agency, or police.
- Refuses independent verification, written information, or time to review the request.
- Sends an unexpected check and asks you to return, spend, or forward part of the money.
A legitimate organization may contact you about a real issue. The safe response is still to end the unexpected contact and reach the organization through an independently verified channel.
How to Protect Yourself
- Pause before acting. Urgency is a reason to verify, not a reason to skip verification.
- Contact the person or organization independently. Use an official website, a number on a statement or payment card, a known application, the UM directory, or contact information you already had.
- Do not use the link or phone number supplied by a suspicious contact. It may lead back to the scammer.
- Discuss unusual requests with someone you trust. Scammers often rely on isolation and secrecy.
- Use strong, unique passwords and MFA. Never share a password or MFA code, and approve only sign-in requests you initiated.
- Keep devices and applications updated. Install software from official sources and do not grant remote access to an unexpected caller.
- Use payment methods that fit the transaction and provide appropriate protections. A demand for an unusual or difficult-to-reverse payment method is a warning sign.
- Review financial and account activity. Enable alerts and investigate transactions, sign-ins, forwarding rules, password changes, or profile changes you do not recognize.
- Limit information shared publicly. Details about work, family, travel, and relationships can be used to make impersonation more convincing.
- Do not pay for a promised refund or recovery. Someone who contacts you unexpectedly and asks for an upfront fee to recover lost money may be operating a second scam.
What You Should Do at UM
If a suspected scam involves a UM email account, device, message, employee or student identity, university data, or UM business process:
- Stop interacting with the request. Do not click links, open attachments, reply, call a number in the message, send money, or provide information.
- Verify the request through an official UM website, the UM directory, or another trusted contact method.
- Use Outlook's Report Message tool and report a suspicious email as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.
- Contact the UM IT Helpdesk or UM Information Security Office when a UM account, device, message, identity, or university process is involved.
- Contact the appropriate UM financial or business office through a trusted method before acting on a request involving payments, banking changes, payroll, purchasing, or vendor information.
If you already interacted with the scam:
- Entered a UM password: Change it through the normal UM account-management process and contact the UM IT Helpdesk or UM Information Security Office.
- Shared an MFA code or approved an unexpected request: Deny further requests and contact UM support immediately.
- Opened an attachment, installed software, or allowed remote access on a UM device: Stop using the affected application or session and contact the UM IT Helpdesk or UM Information Security Office for guidance.
- Sent UM funds or changed a UM financial process: Contact the relevant UM financial office and the UM Information Security Office immediately.
- Shared university data: Do not distribute the information further. Contact the UM Information Security Office so the exposure can be assessed.
For a personal scam that does not involve UM, contact the affected account provider, financial institution, payment service, merchant, platform, mobile carrier, or trusted technical support. UM does not administer personal accounts or transactions, but UM should be notified when a UM account, device, message, identity, or business process was involved.
Additional Questions
For a suspected scam involving UM, contact the UM IT Helpdesk and the UM Information Security Office. Involve the relevant UM financial or business office when university funds or processes are involved.
For a personal scam:
- Contact your financial institution or payment provider immediately if money was sent or account information was exposed.
- Contact the account provider through its official recovery or security process if a personal email, social-media, shopping, or other online account may be affected.
- Report the message or account to the email provider, mobile carrier, social-media service, marketplace, or other platform where it appeared.
- Use trusted technical support from the device manufacturer, service provider, or a provider you selected independently if software was installed or remote access was granted.
- Use IdentityTheft.gov when identifying information has been used, or is likely to be misused, to impersonate you. Do not treat every suspicious message or routine payment dispute as identity theft.
- Report consumer fraud to the Federal Trade Commission. Internet-enabled fraud can also be reported to the FBI's Internet Crime Complaint Center.
Additional Resources