Skip to main content

Phishing Emails – How to spot them and what to do

Published: 28 July 2021 Last updated: 25 January 2024

IT Service

Back to FAQs homepage | Back to / category


3.5
(6)
  1. What is Phishing?
  2. Spotting suspicious messages
  3. If you receive a phishing email
  4. If you have followed a link in a phishing email

1. What is Phishing?

Phishing is a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.

The information is then used to access important accounts and can result in identity theft and financial loss.

2. Spotting suspicious messages

Spotting scam messages and phone calls is becoming increasingly difficult. Many scams will even fool the experts. However, there are some tricks that criminals will use to try and get you to respond without thinking.

Authority – Is the message claiming to be from someone official? For example, your bank, doctor, a solicitor, or a government department. Criminals often pretend to be important people or organisations to trick you into doing what they want.

Spoofing – Is the message claiming to be from someone at the University, but the email doesn’t feel quite right. If it has [External] at the start of the subject field, then it is an external email with a spoofed email address.

Poorly written – You can tell if an email is a scam if it contains poor spelling and grammar, the theory is if you ignore the clues about the way the message is written, you’re less likely to pick up the clues when the scammer plays his endgame.

Urgency – Are you told you have a limited time to respond (such as ‘within 24 hours’ or ‘immediately’)? Criminals often threaten you with fines or other negative consequences.

Emotion – Does the message make you panic, fearful, hopeful or curious? Criminals often use threatening language, make false claims of support, or tease you into wanting to find out more.

Scarcity – Is the message offering something in short supply, like concert tickets, money or a cure for medical conditions? Fear of missing out on a good deal or opportunity can make you respond quickly.

Suspicious links – You can spot a suspicious link if it does not match the context of the rest of the email. If the email is about the University of Worcester, then you would expect the link to go to worc.ac.uk. If you hover over a link it will show you the actual destination address.

Current events – Are you expecting to see a message like this? Criminals often exploit current news stories, big events or specific times of year (like tax reporting) to make their scam seem more relevant to you.

2. If you believe you have received a phishing email

  • Never respond to emails that ask for your password or other sensitive information.
  • Never click on or open suspicious links or attachments.
  • If you’re taken to a login page or website, do no attempt to login or enter personal information.
  • If the email appears to be from someone you know, contact them via a new email or by phone to ask if it is genuine.
  • Report a phishing or junk email in Outlook by using the Report Message button located at the top right-hand side of your screen and select the category that your email falls into. Once reported, the email will be removed from your inbox after a few moments.

3. If you have followed a link in a phishing email

  • If you have entered your University password, you should change it immediately. If you have used this password on other accounts, change it on those as well. Visit this FAQ for guidance on changing your password.
  • If you have entered any financial details, contact your bank immediately and tell them that you have been the victim of an email scam. Do this straight away before moving on to the next step.
  • Contact the IT Service Desk so we can investigate and advise you further on what to do.
  • Run a full anti-virus scan on your computer or device (The anti-virus program on University supplied Windows Laptops is Windows Defender).

How useful was this FAQ?

Click on a star to rate it!

Average rating 3.5 / 5. Vote count: 6

No votes so far! Be the first to rate this FAQ.

We are sorry that this FAQ was not useful for you.

Your feedback helps us improve our content.

Please let us know what was wrong.


Back to top