Email Security: Avoiding Phishing Scams and What To Do if you Clicked!

Knowledge Base Article

How to Avoid Phishing Attacks: Protect Yourself with STOP. THINK. CONNECT.

Audience: Faculty, Staff, Students
Category: Cybersecurity Awareness
Last Updated: July 2026


Overview

Phishing is currently the most common cybersecurity threat facing colleges and universities. Cybercriminals use fraudulent emails, text messages, phone calls, and websites to trick people into revealing passwords, financial information, or other sensitive data. Once they have done that, they can steal your authentication token -- allowing real time access to your emails anytime they want until that token expires.

A single click on a malicious link can lead to:

  • Compromised accounts

  • Identity theft

  • Financial fraud

  • Malware or ransomware infections

  • Unauthorized access to college systems

  • Exposure of sensitive student or employee information

Fortunately, most phishing attacks can be prevented by following a few simple best practices.


Remember: STOP. THINK. CONNECT.

The National Cybersecurity Alliance promotes a simple but powerful approach to staying safe online.

๐Ÿ›‘ STOP

Before clicking a link, opening an attachment, or responding to a message:

  • Pause for a moment.

  • Don't let urgency pressure you into acting immediately.

  • Be cautious of messages claiming your account will be locked, you've won a prize, or immediate payment is required.

Attackers want you to react emotionallyโ€”not logically.


๐Ÿค” THINK

Ask yourself:

  • Was I expecting this email?

  • Do I recognize the sender?

  • Does the message seem unusual?

  • Is the request out of character?

  • Is the email asking me to bypass normal procedures?

  • Is it requesting passwords, MFA codes, gift cards, or financial information?

Look carefully for warning signs:

  • Poor grammar or spelling

  • Generic greetings ("Dear Customer")

  • Unexpected attachments

  • Links that don't match the displayed website

  • Requests for confidential information

  • A sense of urgency or fear

When in doubt, verify using another method such as a phone call or Microsoft Teams message.


๐ŸŒ CONNECT

Before entering your credentials:

  • Verify you are on the legitimate website.

  • Look for the correct web address (URL).

  • Ensure the connection is secure (https://).

  • Use Multi-Factor Authentication (MFA) whenever available.

Only connect to trusted websites and approved college resources.


Common Signs of a Phishing Email

Be cautious if an email:

  • Creates urgency ("Your account expires today!")

  • Requests passwords or MFA codes

  • Asks you to purchase gift cards

  • Claims you've received an unexpected invoice

  • Claims that they are selling big ticket items as cheaply, or even for free if you just respond

  • Includes suspicious attachments

  • Contains unexpected document-sharing requests

  • Comes from an unfamiliar email address

  • Appears to come from a trusted sender but has unusual wording

  • Requests to communicate via private email, and not through the College's email system

Remember:

Cybercriminals can spoof email addresses to make messages appear legitimate.

Always verify suspicious requests.


Before You Click

Hover your mouse over any hyperlink before clicking.

Check whether:

  • The website matches the organization.

  • The domain is spelled correctly.

  • The destination looks legitimate.

  • You are expecting the email and link from the person the email claims to be from.

Example:

Legitimate

https://login.microsoftonline.com

Suspicious

https://micr0soft-login-security.com

Notice the subtle spelling differences.


Attachments Can Be Dangerous

Never open unexpected attachments.  Ever - even if it looks like it is from a trusted sender.

Common risky file types include:

  • ZIP files

  • EXE files

  • ISO images

  • JavaScript (.js)

  • Office documents requesting macros

Even PDF or Word documents can contain malicious content if they ask you to enable editing or macros.


Protect Your Password

Your password is yours alone.

Never share:

  • Passwords

  • MFA approval codes

  • Verification codes

  • Security questions

The College IT Department will never ask for your password by email, phone, or text message.


Be Cautious with QR Codes

Attackers increasingly use QR codes to bypass email security.

Before scanning:

  • Consider whether you were expecting it.

  • Verify the source.

  • Preview the destination if your phone allows it.

If unsure, type the website manually instead.


Watch for Business Email Compromise (BEC)

Some phishing attacks look extremely convincing.

Examples include fake requests from:

  • Supervisors

  • Human Resources

  • Finance

  • Vendors

  • College leadership

They often ask for:

  • Wire transfers

  • Gift card purchases

  • Payroll changes

  • Banking information

  • Sensitive documents

Always verify these requests through a trusted communication method before taking action.


If You Think You've Been Phished

Act quickly.

  1. Stop interacting with the message.

  2. Do not reply.

  3. Report the email using the organization's approved reporting method (such as the "Report Phishing" button in Outlook, if available).

  4. Contact the IT Help Desk immediately.

  5. If you entered your password:

  6. If you approved an unexpected MFA request, contact IT immediately.

The sooner IT is notified, the better the chances of preventing further compromise.


Additional Tips to Stay Safe

  • Use Multi-Factor Authentication (MFA) for all your accounts (even non-CCC accounts). If you would like assistance adding it to your GMail or Yahoo email, ask!)

  • Keep your computer operating system updated

  • Lock your computer when away

  • Never reuse passwords

  • Use a password manager to create strong, unique passwords

  • Be cautious on public Wi-Fi

  • Keep browsers and software up to date


Remember

Cybersecurity is everyone's responsibility. The tools available to secure you only go so far - and your vigilance is a key component to keeping your data, and the College safe!

Most phishing attacks succeed not because of sophisticated technology, but because they exploit human trust and urgency.

Whenever you receive an unexpected request:

๐Ÿ›‘ STOP. ๐Ÿค” THINK. ๐ŸŒ CONNECT.

Taking just a few extra seconds to verify a message can protect not only your own account, but also the entire Cedar Crest College community.


Need Help?

If you receive a suspicious email or believe your account may have been compromised, contact the Cedar Crest College Office of Information Technology immediately by emailing helpdesk@cedarcrest.edu. Reporting suspicious activity promptly helps protect the entire campus community.