Stay Cautious of Phishing
Oops! You were just phished by your IT Security Team.
That's okay. You're human. Let's take a moment to learn from this so you can avoid scams when real hackers strike.
Instead of stealing your data or injecting your system with a virus, we've directed you to this educational page and assigned some training courses that will provide a few helpful tips on how to spot and prevent phishing attempts.
Check your email for details about the courses you've been assigned and review the email example you received below for a few tips on how to catch the phish next time.
Let's Analyze Together
Malicious Request to Review a File
Not from a legitimate email address
How to check: Hover over or click the sender's name and compare the email address to the one listed in the Outlook directory.
Not an expected email from a regular contact
How to check: Ask yourself whether you know this person and whether you were expecting them to send you a file.
Doesn't offer insight into what the file is and context is vague
How to check: Look for a clear explanation of what the file contains and why it was sent to you. Be cautious if details are missing.
Sender physical address unlikely to be associated with USF
How to check: Review the signature block and look for addresses, phone numbers, or other details that do not seem connected to USF.
Malicious Request to Sign a Document
Not from a legitimate email address
How to check: Verify that the sender's email address exactly matches the organization or person they claim to represent.
Not an expected email from a regular contact
How to check: Consider whether this person normally contacts you and whether the message fits your current work activities.
Sense of urgency
How to check: Watch for pressure tactics such as "Act now," "Immediate action required," or threats of negative consequences if you don't respond.
Grammar and language errors
How to check: Look for unusual wording, spelling mistakes, awkward phrasing, or inconsistent capitalization that seems out of place.
Suspiciously erratic formatting and visual design
How to check: Look for mismatched fonts, poor-quality logos, unusual colors, odd spacing, or layouts that don't resemble legitimate organizational emails.
Helpful Tips to Avoid Phishing Attempts
Is the email allegedly coming from a reputable source within your organization?
Cross check the email address against the one listed in your Outlook directory. For example, if the email is supposed to be from Human Resources, does it match the email address on messages you have received from Human Resources in the past? If you try to email HR directly from Outlook, does the same email address pop up?
Is this type of request typical or new?
If you have not received this type of email before, reach out to the department it is associated with directly, or contact IT to verify its legitimacy. It is always OK to ask questions.
If the email is expected and associated with a familiar department, does the format of the email look familiar, or does it seem new and strange to you?
Look for USF branding in the email and familiar names of people you've interacted with in the past. Have you received an email from this department before? If possible, look at the old email to see if the new one looks similar.
Does the email require you to enter too much data or information than what seems necessary? Is it asking you for passwords or codes in unexpected places?
This is a major indicator that you might be dealing with a scammer. USF will never ask you to provide your passwords or MFA codes outside of official login pages/applications.
Was this text, message, email or phone call one that you were expecting? Did this person contact you out of nowhere?
This isn't necessarily a sign of a phishing attempt, but it's still a helpful element of context to consider when evaluating the legitimacy of a communication.
Are there unusual spellings, typos and sketchy links?
Hackers are becoming more sophisticated. We are seeing less obvious signs such as these in phishing emails, however these are still important to watch out for and still frequently appear.