Identify Phishing
Phishing: Don’t take the bait
At Ƶ, we’re seeing a rise in phishing emails that try to take advantage of our busiest moments and our willingness to help one another. These scams are designed to trick recipients into revealing personal information—like passwords, MFA codes, or financial details—and can lead to payroll theft, data breaches, and financial aid fraud. Staying alert protects not only your information, but the people and systems we all rely on every day.
E-mail spoofing involves sending an email that pretends to be from a well-known company, a close family member or a respected individual from your organization. Spoofing can also be carried out in person, over the phone or via malicious pop-up windows or “spoofed” (fake) websites.
How to Spot a Phishing Email
Scammers can create convincing copies of Ƶ pages, Google Forms, and SharePoint portals to steal credentials, often during high-pressure periods during the academic year. Phishing emails often use urgent or threatening language like “Your account will be suspended” or “Immediate action required.” They may also contain suspicious links or attachments and will likely have a generic greeting like “Dear user”, or “Dear Account Holder” instead of your name.
Common ways to spot a phishing email:
- The email comes from you and is addressed to you.
- The email doesn’t address you by name.
- The purpose of the email doesn’t align with a standard business practice.
- The email creates a sense of urgency, invokes fear or other stron emotions.
- The email asks for sensitive, regulated, or personal information.
- The email contains unexpected attachments or links.
- The email contains QR Codes – NEVER scan a QR code that you receive in email.
- Contain links that lead to unfamiliar websites or don’t match legitimate resources for the organization
Your Call to Action
You can be proactive in avoiding cyber security dangers and ensure you don’t Take The Bait or Feed the Phish.
- Pause before you click. Ask yourself:
- “Is this how Ƶ normally communicates?”
- “Is this how job openings are usually shared?”
- “Does Ƶ IT ever send emails for account verification or ask for my password or MFA code by email?”
- “Does this match how Ƶ typically shares files or requests data?”If you are not sure, check with your supervisor. Ƶ will never ask for your password, credentials, or MFA codes by email.
- Report suspicious messages. If you receive a phishing or a suspicious email, report the email by using the “Report Phishing” button in Outlook or forward the message to infosec@elon.edu. Using the report button is quicker and will more efficiently provide containment and remediation of the attack.

- Stay informed. Completing security awareness training will help you stay informed regarding existing threats, scams and attacks. Hover over links to check for authenticity
- If you receive a phishing or suspicious email, act fast. Your quick response will help to identify, contain and remediate the attack. If you do respond to a phishing email, contact the Service Desk immediately (X5200)
Have you been scammed?
If you think you’ve been the victim of a phishing scam:
- Change any passwords immediately
- Scan your computer or device for viruses
- Review activity for email and accounts
- Contact your bank to report that you may have been the victim of fraud
- If your Ƶ issued computer or device has been compromised, contact Campus Technology Support immediately at (336) 278-5200