How to Detect Phishing Attacks
Telling the difference between a legitimate email, instant message or popup and a fraudulent one is not easy. If you receive any email or other message on your computer requesting personal information (such as an account name, password, date of birth, or social security number), please review the following information before continuing any further.
Colby Information Technology Services (ITS) will NEVER ask for your personal information over email. Furthermore, you should always avoid sending any personal information via email.
What is fraudulent or ‘phishing’ email?
Phishing is a type of online scam that targets consumers by sending them an e-mail that appears to be from a well-known source – an internet service provider, a bank, or a mortgage company, for example. It asks the consumer to provide personal identifying information. Then a scammer uses the information to open new accounts, or invade the consumer’s existing accounts (www.ftc.gov)
Types of Phishing to Watch For
- Artificial Intelligence (AI) -Polished Emails: Attackers use AI tools to generate highly realistic, error-free emails customized to specific departments or staff members.
- QR Code Phishing: Messages containing QR codes that direct you to malicious login pages designed to bypass traditional email security filters.
- Multi-factor authentication (MFA) Push Fatigue & Token Theft: Malicious links that direct you to fake login pages designed to capture both your password and your multi-factor MFA codes or session tokens in real time.
- Job and Research Scams: Highly targeted emails offering lucrative "work-from-home" positions, research assistants, or grants. These often involve fake check scams or request personal financial details upfront.
- Very Important People (VIP) Impersonation: Urgent messages appearing to come from the deans, professors, or supervisors requesting quick actions, such as purchasing gift cards or transferring funds.
Common Red Flags of fraudulent email
- Unusual Urgency or Pressure: Demands for immediate action, threatening account suspension, or warning of severe consequences if you do not act right away.
- Sender Address Mismatches: The display name may say "Colby ITS" but hovering over or expanding the actual email address reveals a non-Colby or spoofed external domain.
- Requests for Unnecessary Sensitive Data: Unsolicited prompts for credentials, MFA passcodes, SSNs, or financial details.
- Suspicious Links or QR Codes: Directives to scan a QR code or click links pointing to unfamiliar or direct IP web addresses (e.g., http://10.42.107.92 or misspelled domain names).
- Inability to Verify Identity: The sender claims they are unable to speak on the phone, join a video call, or meet in person to confirm the request.
What to do if you receive email you suspect is fraudulent?
- Delete it. These emails are generated by the same computers who bring spam to your inbox on a daily basis.
- Call the person who sent it and ask if they really sent it.
- Never click on a link in a fraudulent email or message—it may make matters worse by introducing viruses or potentially unwanted programs to your device.
Steps to take if you have responded to a phishing attempt
If you think you may have accidentally responded to a phishing attempt, make sure to immediately change any accounts or passwords that may have been compromised. If it is a Colby account, follow the instructions here: https://colby.teamdynamix.com/TDClient/1928/Portal/KB/ArticleDet?ID=141586. If it is a vendor (bank, credit card, online merchant) account, contact that vendor to have your information changed.
Test yourself. How well can you identify fraudulent email?
https://www.sonicwall.com/phishing-iq-test/
As always, if you have questions about email fraud or computer security, contact Colby ITS support desk for assistance – support@colby.edu or ext. 4222.
Colby ITS does our best to link to only the best external sites. However, this content is out of our control and subject to external changes. Please use the feedback option at the bottom of this article if you find links to be in error.