Phishing Scams
Phishing is a way cybercriminals try to trick you into sharing personal information, such as passwords, credit card numbers, Social Security numbers and bank account numbers, by sending fraudulent emails or text messages that direct you to a fake website.
Phishing is designed to appear as though it comes from a legitimate organization, such as K-State, PayPal, FedEx, your bank or a government agency. The email or text message often asks you to update or verify account information or claims there is an urgent problem that requires immediate action. If you click the link, you may be taken to a fraudulent website and tricked into entering your information, which can compromise your accounts or lead to identity theft.
K-State and legitimate organizations will never ask you to provide your account credentials, personal information or financial information through an email or text message.
Report Phishing Email
Send the suspected phishing email and original headers to: abuse@k-state.edu.
Signs It's a Scam
Learn to recognize a phishing scam and help protect yourself from identity theft.
- Urgent or threatening tone.
- Email address doesn't match sender's name.
- Unexpected attachments.
- Generic greeting.
- Typos, misspellings, and improper grammar.
- Fake web addresses made to look legitimate.
- Link text and destination differ when hovered over.
If You Think You've Fallen for a Phishing Scam
- Change your password immediately.
- Disconnect from the network (turn off Wi-Fi or unplug Ethernet) and alert your system administrator, who will check to determine if any malware has been put on your machine and remove it. If you don't have a system administrator, contact the IT Service Desk: Submit a Ticket, or Start a Live Chat.
- Do not power off the device unless specifically instructed to do so.
- Check whether your email forwarding has been changed.
- From your eProfile page, check your alternate email address to ensure it hasn't been changed.
- Check your eID password-reset options to verify they haven't been changed.
- If you use similar passwords on other accounts (bank account, healthcare, retirement, etc.) change those passwords as well.
- For the next year, review your bank and credit card statements to check for suspicious activity. Change passwords on all relevant accounts.
NOTE: Cybercriminals will sometimes hold personal identity information and use it much later. - Check your Sent and Drafts email folders to see if your account has been used to send additional scams to other people. Delete any emails in Drafts to keep them from being sent, and notify recipients of any Sent emails that your previous email was a scam. Use some method other than email to notify those people.
Preventative Strategies
- Don't reply to suspicious, unexpected, or strange email.
- Be wary of email with urgent requests for your personal or financial information, or your sign-in credentials.
- Don't open unexpected or unusual attachments, attachments from strangers, or strange-looking emails.
- Don't click links in unexpected emails, emails you suspect are fraudulent, or if you don't know the sender.
- Don't click Sign In links. Go to the business website and sign in there, or contact their customer service for help.
- Avoid filling out forms in email messages that ask for financial information. Only share credit card information via secure website or telephone.