You’ve been phished

How to recognize and defend against phishing attacks.

REMEMBER THE RULES OF FIGHTING PHISHING:

  1. Don’t trust links or attachments
  2. Just because the email address looks legitimate doesn’t mean it is
  3. If you aren’t expecting an email with a link or attachment, call (don’t use the phone number in the email) or email (through a separate email to their normal address) the person to ask if it is legitimate. Don’t click until you are sure
  4. Make sure the email address or URLs aren’t mis-spelled.
    1. Misspellings are used to trick people into clicking a seemingly legitimate URL that isn’t, e.g., micrsoft.com (missing “o”) or rnicrosoft.com (notice the “m” in this is actually an “r”  and an “n” next to each other, because it looks like an “m”)
  5. Hover your cursor over the web link to see the URL. If the URL looks funny, don’t click and go to #3