skip to content

IT Help and Support

University Information Services
 

'Phishing' is where a scammer attempts to use social engineering techniques to encourage you to disclose personal information, account login details or financial information. They then use it as part of other scams.

What should I do if I receive an unexpected or suspicious email?

We strongly advise exercising caution before clicking links or downloading attachments in emails, especially if you were not expecting an email.

Look out for common signs of social engineering employed by malicious senders:

  • Urgency, where the sender is pressuring you to respond quickly. Common examples include suggesting your account will be deactivated unless you verify your password via a link. They may imply that something will go wrong, or you may miss out on an opportunity, if you do not reply by a deadline.
  • Authority, where the sender pretends to be someone more senior and states that certain actions are required. They are depending on the tendency of people to follow directions from perceived leadership.
  • Social proof, where the sender suggests that others at the University have completed an action, and therefore you should also follow their prompts.

Think before you click – especially if the email is unexpected. Email accounts can be compromised and abused to circulate phishing emails to other people. Bad actors want recipients to trust communication from a Cambridge sender, but it’s important to employ a healthy amount of scepticism when you receive an email.

  • Unexpected emails might not be safe. This includes emails with file share links, including SharePoint, or emails claiming to offer something rewarding (like gifts, money, or a promotion).
  • If possible, verify an unexpected email with the sender via a different communication channel. For example, if you receive an unexpected email, try calling the sender asking them to confirm that they sent it.
  • When in doubt, report the email to spam@uis.cam.ac.uk and your local IT team. We will review phishing emails reported to the UIS Service Desk team.
  • In the past, phishing emails often had poor grammar and spelling mistakes, which was a giveaway. However, AI has enabled bad actors to write increasingly sophisticated and grammatically correct emails.
  • If you clicked a malicious link, it’s best practice to change your password to something stronger and unique from other accounts. Read our guide on choosing a strong password and keeping it safe
  • After changing your password, sign out of all devices and sign back in. You can sign out of all sessions by visiting https://mysignins.microsoft.com/security-info and clicking the 'Lost Device? Sign Out Everywhere'.
  • It is also best practice to run a full antivirus scan on the device where you clicked on a phishing link. If you need support, please contact the UIS Service Desk or your local IT team.
  • UIS and your local IT team will never contact you asking for your credentials or ask you to sign in on a page to verify your identity.

 

Watch our short videos on our MyCompliance platform:

What is Phishing and how do I recognise it (3:45)

Learn more about Phishing (11:43)