
Phishing and Scam Awareness
Phishing is a type of social-engineering attack in which criminals impersonate a trusted person or organization to trick you into revealing information, approving a sign-in, sending money, or opening a malicious link or attachment.
Phishing can arrive through email, text message, phone call, social media, QR code, or collaboration tools. Attackers may impersonate a university department, supervisor, student, vendor, bank, government agency, delivery service, or Microsoft 365 account notification.
When in doubt, do not click. Pause and verify the request using a contact method you already know is legitimate.
How to Recognize Phishing
Phishing messages often contain one or more warning signs. A message does not have to contain spelling mistakes or poor grammar to be malicious—many current attacks are polished, targeted, and convincing.
- Unexpected urgency or pressure. The sender demands immediate action or threatens account closure, missed payment, disciplinary action, lost files, or other consequences.
- Requests for passwords, MFA codes, personal information, or financial information. Legitimate IT staff should not ask you to send your password or multi-factor authentication code by email, text, chat, or phone.
- A suspicious sender address. Check the complete email address, not only the display name. Look for misspellings, extra words, or look-alike domains.
- Unexpected links, attachments, shared files, or QR codes. Be especially cautious if you were not expecting the message or document.
- Links that do not match where they claim to go. On a computer, hover over a link before selecting it. On a mobile device, press and hold when appropriate to inspect the destination.
- Unusual payment or purchasing requests. Gift cards, wire transfers, cryptocurrency, changed bank details, or “urgent” invoice requests are common scam tactics.
- An unusual request from someone you know. A compromised account can send convincing messages from a real colleague, friend, or organization.
- Unexpected sign-in or MFA prompts. Do not approve a sign-in notification that you did not initiate.
What to Do With a Suspicious Message
- Do not click links, open attachments, scan QR codes, reply, call phone numbers in the message, or use an “unsubscribe” link.
- Report the message to Truman IT. Use the TitanHQ add-in in Outlook to flag the email as phishing.
- Delete the message after reporting it.
- Verify independently if necessary. Type a known website address into your browser, use a phone number from an official website or previous statement, or contact the person through a known method.
If You Clicked or Responded
Act quickly. Reporting promptly can help protect your account, your coworkers, and the University.
- If you entered your Truman password on a suspicious website, change your password immediately using the official Truman password-management process.
- If you approved an unexpected multi-factor authentication prompt, report it immediately and change your password.
- If you opened an attachment, downloaded a file, or installed software, disconnect from the network if instructed by IT and contact the IT Service Center as soon as possible.
- If you shared financial, identity, or other sensitive personal information, notify the affected institution directly using contact information from its official website or your account statement.
- Preserve useful details for IT: the sender address, message subject, time received, links or attachment names, and any steps you took.
Do not be embarrassed to report a mistake. Phishing attacks are designed to create urgency and bypass normal caution. Fast reporting is the right response.
Protect Your Accounts
- Use a unique, strong password for every account. A password manager can help create and store unique passwords.
- Use multi-factor authentication whenever it is available.
- Keep your computer, phone, browser, and applications updated.
- Review account activity and sign-in alerts, particularly after receiving a suspicious message.
- Be cautious with information posted publicly online; attackers can use it to make messages more convincing.
- Use approved University systems and processes for sensitive information, payments, account changes, and document sharing.
Related Scams
- Smishing: Phishing delivered by text message or SMS.
- Vishing: Phishing delivered by phone call, voicemail, or voice message.
- Business email compromise: An attacker impersonates an executive, employee, vendor, or trusted contact to request payment, payroll changes, gift cards, or sensitive information.
- QR-code phishing: A malicious QR code directs you to a fraudulent website, often designed to capture credentials or MFA approvals.
- Credential-harvesting sites: Fake sign-in pages that imitate Microsoft 365, banks, package-delivery services, and other familiar services.
External Reporting and Resources
- CISA: Recognize and Report Phishing
- FTC: How To Recognize and Avoid Phishing Scams
- Report fraud or scams to the Federal Trade Commission
- FBI Internet Crime Complaint Center (IC3)
- Forward phishing email to the Anti-Phishing Working Group
For phishing emails, the FTC also recommends forwarding the message to the Anti-Phishing Working Group at reportphishing@apwg.org and reporting the scam through ReportFraud.ftc.gov. [16][1]