"Phishing" refers to the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.
Like all universities, Appalachian State University is frequently phished for account credentials.
A Phishing attempt for account credentials usually starts with an email that indicates that you MUST do something to validate, extend your storage, view quarantined messages, etc. The message will almost always convey a sense of urgency. This is an attempt to get you to act quickly without thinking.
Here are a few important things to remember about Phishing attempts:
- Always remember that ITS will never ask to provide your password via phone, email, or any other communication medium.
- Keep in mind that phishing emails can appear very legitimate and include the same images, logos, and text associated with the organizations they are attempting to impersonate. Do not rely solely on the appearance of an email or website as a mark of legitimacy.
- Also, be aware that the 'From' field in email messages can easily be fabricated. Don't assume that an email is legitimate based on the apparent sender in the "From" field.
If you receive a call from a student/employee/Authorized user regarding a Phishing attempt, please ensure contact information is documented on the ticket and escalate to level 2.
Comments
0 comments
Please sign in to leave a comment.