Beware and Stay Vigilant: How to Spot and Avoid Phishing Scams

Phishing emails remain one of the most common ways attackers gain access to University systems and personal information. If you receive an email requesting that you click a link, provide your username and password, share personal information, or open an attachment, proceed with caution. These requests are common indicators of a phishing attempt.

These emails often appear legitimate. Do not assume a message is safe based on how it looks; verify before you act.

Red flags to watch for:

  • Messages that create urgency or threaten consequences if you do not act immediately
  • Requests for login credentials, verification codes, or payments
  • Sender addresses or domains that closely resemble, but are not, official university accounts
  • Unexpected links or attachments
  • Generic greetings or noticeable grammar and spelling issues
  • Unsolicited job offers, including work-from-home, remote, or part-time opportunities
  • Messages promising high pay for minimal effort or requiring upfront information or payment
  • Requests to move communication off email to text messaging or personal email accounts

If you suspect an email is a phishing attempt:

  • Do not click links or open attachments
  • Do not reply to the message
  • Report it immediately to the UMW IT Security Office at abuse@umw.edu, or contact the UMW Help Desk at HelpDesk@umw.edu or 540‑654‑2255 so the issue can be investigated.
  • Delete the message after reporting it to prevent further security risks.

When in doubt, stop and verify. A quick call can prevent a security incident. Your vigilance protects both your information and the University.