ping - 26-02: Phishing

Phishing refers to the method a bad actor uses to get sensitive information from a victim.  The bad actor attempts to mislead the victim often be pretending to to be someone (or an organization) that the victim is familiar. The bad actor may request specific information or use a fake login page to capture login credentials. These deceptive messages can appear in both personal and university email accounts.

How Do You Identify a Phishing Email?

  1. Unknown Senders
    Many phishing emails come from unknown, unfamiliar, or suspicious email addresses. While the university’s official email domain is msstate.edu, keep in mind that an MSU email account can potentially be compromised. Always check the sender’s full email address and make sure it is someone you recognize or an official university account. If you are unsure, forward the email message as an attachment to servicedesk@msstate.edu for inspection.

  2. Spelling and Grammatical Mistakes
    Poor spelling, grammar, or awkward wording can be a common sign of a phishing or spam email. The university strives to maintain professional, high-quality communication in its official emails, so unusual errors or phrasing should raise a red flag.

  3. Suspicious Links or Unexpected Attachments
    Be cautious when an email contains unexpected links or attachments. If you are unsure about a link, hover over it without clicking to see where it leads. If the destination looks unfamiliar or does not match the organization that sent the email, do not click it.

  4. Requests for Duo Mobile Codes or Approvals
    ITS will never ask you to provide a Duo Mobile passcode. You may occasionally receive a Duo push notification when you are actively working with ITS on an issue, but you should never approve an unexpected authentication request.

  5. Trust and Urgency
    Phishing emails often try to build trust while creating a sense of urgency. Attackers may claim that your account will be disabled, a payment is due, or immediate action is required. Be cautious of emails that pressure you into acting quickly or providing sensitive information.

  6. Strange or Unexpected Requests
    Phishing emails may contain unusual requests that seem out of place. Be cautious if an email asks you to provide personal information, send money, change account settings, or perform an action you would not normally expect from the sender.

 

 

What do you do when you receive a phishing e-mail?

  1. Do not click on any links or attachments.

  2. Forward the e-mail as an attachment to servicedesk@msstate.edu for inspection.

  3. Delete the suspicious e-mail.

 

Additional Information:


Help the ITS Service Desk help you!

  • Never submit a form if it displays sensitive information such as a social security number or a password as plain text.
  • If it sounds too good to be true, it probably is!
  • If it causes you panic, take a second to breathe and take a closer look.
  • Check the timing of the e-mail! Does it really make sense to receive it at that moment?

Return to ping