Account & Security
Understanding Phishing
Phishing is one of the most common types of cyberattacks and is designed to trick you into sharing sensitive information, such as your username, password, Multi-Factor Authentication (MFA) code, financial information, or other personal data.
Attackers often disguise themselves as trusted organizations, businesses, or even people you know in an attempt to gain your trust. While phishing emails have become much more convincing over the years, there are still several warning signs that can help you recognize and avoid them.
This guide will help you identify common phishing attempts and provide best practices for protecting your personal information.
Phishing Warning Signs
Common Signs of a Phishing Attempt
If you receive an email, text message, or phone call requesting sensitive information, take a moment to review the following warning signs before responding.
Check the Sender's Email Address
One of the easiest ways to identify a phishing email is by looking closely at the sender's email address.
Attackers frequently create email addresses or domains that look almost identical to legitimate organizations.
Examples:
✅ highlandscollege.edu
Official Highlands College domain
❌ highlandscolledge.edu
Contains a small spelling mistake that's easy to overlook.
❌ highlandscollege-support.com
Looks official, but it is not a Highlands College domain.
Tip: Always verify the sender's email address before clicking links or responding to a message.
Check for Spelling and Grammatical Errors
Many phishing emails contain spelling mistakes, awkward grammar, or unusual wording.
Historically, these errors have been common because attackers often operate in countries where English is not their primary language.
Keep in mind: With the increased use of artificial intelligence (AI), phishing emails are becoming much more polished and grammatically correct. While poor grammar can still be a warning sign, it should not be the only factor you use to determine whether an email is legitimate.
Look for Harsh or Threatening Language
Phishing attacks often rely on creating a sense of urgency.
Attackers want you to react quickly before you have time to think or verify whether the message is legitimate.
Be cautious of emails that include statements such as:
- "Your account will be deleted within 24 hours."
- "Immediate Action Required."
- "Failure to respond will result in disciplinary action."
- "Verify your account immediately."
Whenever possible, slow down and verify the request before taking any action.
Check Links Before Clicking
Never assume a hyperlink will take you to the website it claims to represent.
Most email programs allow you to hover your mouse over a link to preview the actual destination before clicking.
Tip: Always verify where a link is taking you before clicking.
Look for Generic Emails or Unexpected Attachments
Generic greetings and unexpected attachments are common signs of phishing attempts.
Because phishing emails are often sent to thousands of people at once, attackers typically avoid using your name.
Examples include:
- "Dear Student"
- "Dear Customer"
- "Dear User"
Instead of addressing you personally. Unexpected attachments should also be treated with caution.
Common attachment types include:
- .zip
- .jpeg
- .docx
- .xlsx
Malicious files can install harmful software on your device without your knowledge.
If you weren't expecting the attachment, contact the sender through another trusted method before opening it.
How to Protect Your Personal Information
Following these best practices can significantly reduce your chances of becoming a victim of phishing.
Verify the Sender
Whenever possible, contact the sender through another trusted method to confirm they actually sent the message.
Never Enter Sensitive Information Through Email Links
Never click links asking for:
- Your username
- Password
- Multi-Factor Authentication (MFA) code
- Banking information
- Personal identification information
Instead, open your web browser and visit the organization's official website directly.
Don't Trust Phone Numbers Listed in Emails
If you receive an email claiming to be from your bank or another organization, don't call the phone number provided in the email.
Instead, use the official phone number found on:
- The organization's website
- The back of your debit or credit card
- Previous verified correspondence
Don't Open Unexpected Attachments
Only open attachments if:
- You know who sent them.
- You were expecting to receive them.
- You've confirmed the attachment is legitimate.
When in doubt, don't open it.
Use Strong Passwords
Create strong passwords using a combination of:
- Uppercase letters
- Lowercase letters
- Numbers
- Special characters
What to Do if You Receive a Phishing Attempt
If you believe you've received a phishing email or text message:
Take Immediate Action
- Do not click any links.
- Do not download any attachments.
- Do not reply to the message.
- Report the phishing attempt to the appropriate Highlands College contact.
- Delete the message after reporting it.
If you believe you've accidentally entered your Highlands College username or password into a phishing website:
- Change your password immediately.
- Contact the Highlands College Technology Support Team as soon as possible.
- Notify the Technology Support Team if you approved an MFA request that you did not initiate.
Need Additional Help?
If you have any questions about phishing or cybersecurity, the Highlands College Technology Support Team is here to help.
We're committed to providing you with the knowledge and resources you need to keep your accounts, devices, and personal information secure.
If you ever receive a suspicious email, text message, or phone call and aren't sure whether it's legitimate, don't hesitate to contact us at support@highlandscollege.edu .
Comments
0 comments
Article is closed for comments.