Phishing simulation of the month: August 2024
The Information Security and Data Privacy (ISDP) office sends monthly simulated phishing emails to staff in Central Administration, FAS, and some Schools. This program provides members of the community with experience identifying and reporting phishing emails in a safe environment, in addition to gathering valuable metrics to help improve our security services. These simulated emails are based on real phishing attempts seen at the University.
After each email is sent, we’ll break down the key characteristics of the phishing attempt so that you know what to look for in future. August's simulation falsely claimed to be from "Eventbrite" with a fictious story about problems with your ticket purchase.
What you were asked to do:
Click the link in the email to view and download your data.
What to watch for:
The following clues revealed that something was phishy about this email:
- Impersonal greeting: A general salutation was used instead of your name
- Suspicious request: You were asked to click on a link
- Immediate attention needed: There was a sense of urgency
- Bad link: The link did not take you to an Eventbrite website. Although hovering over links has been removed from the browser version of Outlook, you can still right click the link, copy it, and paste it into a text editor like Notepad to inspect the link. You are still able to hover when using the Outlook application.
Want more information on phishing?
Visit our website to learn more about phishing, what to watch for, and how to report a suspected phish.