
Phishing remains one of the most common—and costly—types of cyberattacks. Cybercriminals use carefully crafted emails to impersonate trusted organizations or individuals, hoping to trick you into revealing sensitive information, clicking on a malicious link, or opening a dangerous attachment. While phishing emails may look convincing, there are always warning signs if you know what to look for.
How to Recognize a Phishing Attempt
- Unexpected Requests: Be cautious of emails that pressure you into making payments, sharing personal data, or clicking on links you didn’t ask for or are not relevant to you.
- Urgency or Threats: “Act now” or “your account will be closed” are common tactics used to trick you into taking a hasty action.
- Suspicious Links: Hover your mouse over any hyperlink. If the web address looks odd or doesn’t match the sender, don’t click.
- Mismatched Email Address: Even if the display name looks familiar, double-check the actual sender’s email. Look for small spelling changes or free email services where a known organization’s domain should be.
- Unexpected Attachments: Attachments from unknown or unusual sources should be treated with extreme caution.
- Polished Language Can Be Deceptive: It was once good advice that spelling, grammar, or formatting errors served as a warning sign of phishing. While that is still sometimes true, modern tools—including AI—make it easier for scammers to craft messages that are virtually error-free and written in a convincing tone. Don’t rely solely on language quality to determine whether an email is legitimate. Look for red flags in the context.
Why Reporting Matters
It can be tempting to just delete a suspicious message and move on, but reporting it does much more good. By flagging phishing attempts, you protect others, help improve detection, and raise awareness, making phishing less effective across the community.
What to Do
If you receive a suspicious email, pause and carefully evaluate it. Use the “Report phishing” option in Gmail (three dots in the upper right corner of the message) to alert ITS and contribute to Google’s spam and phishing detection. For more details on how to report phishing, check out 1 Minute on How to Report Phishing.
If you’re unsure whether a message is legitimate, verify with the supposed sender using a known, trusted method—not by replying to the suspicious email. Taking even a few moments to pause and confirm can prevent significant harm to you or the college.
Phishing works because it manipulates trust and emotion. By staying alert, recognizing the signs, and reporting suspicious messages, you help defend not only yourself but the entire campus.
Go deeper on this topic by checking out the resources found here.
Town Hall Recording Available
If you missed the cybersecurity town hall, CyberPop Daemon Hunters, the recording is now available. The recording does not require authentication to view, so it is suitable for sharing with all audiences.
Stay safe out there.
Kendall George
Information Security Officer
Carleton and St. Olaf Colleges