Classes are back in session; scammers never left
A new semester means full inboxes, new schedules and plenty of messages competing for your attention. Scammers take advantage of that activity by sending messages designed to look like routine requests from people and services you trust.
And scams aren’t limited to email. They can arrive through text messages, shared documents, QR codes, social media and other familiar services.
Scammers do their homework.
Public information can make a fake request feel real. Here are some tactics to watch for this semester.
Fraudulent job offers
Be cautious of unexpected job opportunities, particularly those offering high pay for little work or asking you to provide personal information, purchase equipment, deposit a check or send money.
A message may use the name of a real K-State employee, professor or department to make the offer more convincing.
Impersonation scams
Scammers may impersonate university leaders, supervisors, colleagues or other trusted campus roles. They can use names, job titles and other information available online to make a message appear legitimate.
Pay attention to unusual requests, especially messages asking you to act quickly, provide information, purchase something or move the conversation to another communication method.
Account-verification notices
Messages claiming there’s a problem with your account may ask you to verify your identity, password or other information.
Don’t use the link in the message to check your account. Instead, go directly to the service using a website or app you already know and trust.
Shared documents and signature requests
An unexpected document-sharing or electronic-signature notification can easily look like routine university business.
Before opening a document or signing in, consider whether you were expecting it. If you’re unsure, contact the sender another way to verify the request.
Invoices and payment changes
Treat unexpected financial requests with extra caution, including requests to pay an invoice, change payment or banking information, purchase gift cards or send money.
Even when the request appears to come from someone you know, verify unusual financial requests through an established contact method.
Requests for your personal phone number
A scam may begin with a simple message that appears to come from someone you know: “Are you available?” or “Send me your cell number.”
Moving the conversation to text gives the scammer another way to communicate with you and can make later requests seem more personal and believable.
Unexpected Duo or authentication requests
An unexpected authentication request may mean someone is trying to access your account. Never approve a Duo or other authentication request you didn’t initiate.
Text messages
The same tactics used in phishing emails can arrive by text. A message may claim there’s a problem with your account, impersonate someone you know or ask you to respond urgently.
Be cautious when an unexpected text asks you to click a link, provide information or move quickly.
QR codes
Treat QR codes like links. A malicious QR code can send you to a fake website or sign-in page designed to steal your credentials or other information.
Before scanning a QR code, consider where it came from and whether you expected it, especially when it arrives in an unsolicited email or message.
Social media and messaging platforms
Scammers can impersonate people and organizations on social media and messaging platforms, too.
Watch for unexpected direct messages, unusual requests, links to sign-in pages and messages from accounts that appear familiar but don’t sound quite right.
When in doubt, verify another way
You don’t have to figure out exactly how a scam works before deciding not to engage with it.
If a request is unexpected or unusual, verify it through a contact method you already know and trust. Don’t reply to the suspicious message, click its links or use the contact information it provides to determine whether the message itself is legitimate.
A quick verification with the person or organization can prevent a convincing message from leading to a compromised account.
Report any suspicious communications to abuse@k-state.edu.