Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

What is Phishing?

...

You may not realize it, but you are a phishing target at work and at home. you and your devices are worth a tremendous amount of money to cyber criminals, and they will do anything they can to hack them. YOU are the most effective way to detect and stop phishing. If you identify an email you think is a phishing attack, or you are concerned you may have fallen victim, contact your help desk or security team immediately. To learn more about phishing or to demo the SANS Securing The Human phishing testing platform, please visit http://www.securingthehuman.org/phishingSecurity Awareness Website.


Phishing Indicators

A. Check the email addresses. If the email appears to come from a legitimate organization, but the "FROM" address is someone's personal account, such as @gmail.com or @hotmail.com, this is most likely an attack. Also, check the "TO" and "CC" fields. Is the email being sent to people you do not know or do not work with?

...

Send any phishing emails you receive, including its full header information, to the Fredonia Information Security Office (ISO) at security@fredonia.edu.

  • If you suspect it may be a phishing email, Fredonia ISO can review the message and advise if it is legitimate or not.
  • Never respond to any email with confidential information. Fredonia and other legitimate businesses will never ask for this information via email.
  • Use your mouse to hover over links in an email. This will show you the actual website you will be directed to if you click on the link. It is always best to type the address yourself into your web browser, rather than clicking a link in an email.

What should I do if I clicked on a link, opened an attachment or provided information via a phishing email?

  • Contact the Email the Fredonia ITS Service Center immediately at immediate or call 716-673-3407 / its.servicecenter@fredonia.edu.
  • If you entered your password, change it immediately.
  • If clicked on the link, but did not enter your password, please check that your computer security or anti virus program is on and up to date.
  • Depending on the type of phishing attempt, you may need to check you other online accounts (e.g. financial etc.).

...

  • Beware of messages that claim your account has been suspended
  • Be suspicious of any email containing urgent requests for personal financial information
  • Never click on a link in an email. Instead, always type the legitimate Web address of the site you want to reach directly into your Web browser.
  • Be suspicious of email messages and other electronic communications from sources you do not know or recognize
  • Use the latest versions of your operating system (OS) and applications
  • Have the latest security software updates (patches) installed. This includes patches for your OS and applications
  • Keep your anti-virus software up to date
  • Report any suspicious emails
  • Avoid and report phishing emails in Googlehttps://support.google.com/mail/answer/8253?hl=en#zippy=%2Creport-a-phishing-email  

    Avoid and report phishing emails

...