Identify Phishing
Phishing: Don’t take the bait
At Elon, we鈥檙e seeing a rise in phishing emails that try to take advantage of our busiest moments and our willingness to help one another. These scams are designed to trick recipients into revealing personal information鈥攍ike passwords, MFA codes, or financial details鈥攁nd can lead to payroll theft, data breaches, and financial aid fraud. Staying alert protects not only your information, but the people and systems we all rely on every day.
E-mail spoofing involves sending an email that pretends to be from a well-known company, a close family member or a respected individual from your organization. Spoofing can also be carried out in person, over the phone or via malicious pop-up windows or 鈥渟poofed鈥 (fake) websites.
How to Spot a Phishing Email
Scammers can create convincing copies of 福利亚洲国产精品 pages, Google Forms, and SharePoint portals to steal credentials, often during high-pressure periods during the academic year. Phishing emails often use urgent or threatening language like 鈥淵our account will be suspended鈥 or 鈥淚mmediate action required.鈥 They may also contain suspicious links or attachments and will likely have a generic greeting like 鈥淒ear user鈥, or 鈥淒ear Account Holder鈥 instead of your name.
Common ways to spot a phishing email:
- The email comes from you and is addressed to you.
- The email doesn’t address you by name.
- The purpose of the email doesn’t align with a standard business practice.
- The email creates a sense of urgency, invokes fear or other stron emotions.
- The email asks for sensitive, regulated, or personal information.
- The email contains unexpected attachments or links.
- The email contains QR Codes – NEVER scan a QR code that you receive in email.
- Contain links that lead to unfamiliar websites or don’t match legitimate resources for the organization
Your Call to Action
You can be proactive in avoiding cyber security dangers and ensure you don’t Take The Bait or Feed the Phish.
- Pause before you click. Ask yourself:
- 鈥淚s this how Elon normally communicates?鈥
- 聽鈥淚s this how job openings are usually shared?鈥
- 鈥淒oes Elon IT ever send emails for account verification or ask for my password or MFA code by email?鈥
- 鈥淒oes this match how Elon typically shares files or requests data?鈥滻f you are not sure, check with your supervisor. Elon will never ask for your password, credentials, or MFA codes by email.
- Report suspicious messages. If you receive a phishing or a suspicious email, report the email by using the 鈥淩eport Phishing鈥 button in Outlook or forward the message to infosec@elon.edu. Using the report button is quicker and will more efficiently provide containment and remediation of the attack.

- Stay informed. Completing security awareness training will help you stay informed regarding existing threats, scams and attacks.聽 Hover over links to check for authenticity
- If you receive a phishing or suspicious email, act fast. Your quick response will help to identify, contain and remediate the attack. If you do respond to a phishing email, contact the Service Desk immediately (X5200)
Have you been scammed?
If you think you鈥檝e been the victim of a phishing scam:
- Change any passwords immediately
- Scan your computer or device for viruses
- Review activity for email and accounts
- Contact your bank to report that you may have been the victim of fraud
- If your Elon issued computer or device has been compromised, contact Campus Technology Support immediately at (336) 278-5200