Phishing Awareness
What is a phishing email?
A phishing email is a common scam that attempts to lure you into revealing your username, password, or other sensitive information by disguising as someone you know and trust. Although this can be done by phone, it is typically done by email. Phishing emails are disguised as legitimate messages often with malicious links or attachments.
Why does it matter?
Your username and password are extremely valuable and can cause a lot of damage if put in the wrong hands. Once they have this information, the criminals use the information gathered to commit identity theft, attack an organization’s computer network to steal data or to steal money. Criminals use phishing emails because it’s easy, cheap and effective. Email addresses are easy to obtain, and emails are virtually free to send. With little effort and cost, attackers can quickly gain access to valuable data. Those who fall for phishing scams may end up with malware infections, including ransomware, identity theft and data loss.
What is malware and ransomware?
Malware is malicious software, which - if able to run - can cause harm in many ways, including:
- causing a device to become locked or unusable
- stealing, deleting or encrypting data
- taking control of your devices to attack other organizations
- obtaining logins/passwords which allow access to your organization’s systems or services that they use
- allowing access to other accounts, like a bank account, that allows the criminal to steal your money
Ransomware is a type of malware that prevents you from accessing your computer (or the data that is stored on it). The computer itself may become locked, or the data on it might be stolen, deleted or encrypted. Some ransomware will also try to spread to other machines on the network. The criminals then ask for money to give you your files back or they will put you or your organization’s information out on the internet. Ransomware infections usually start with a malicious email. An unsuspecting user opens an attachment or clicks on a link in the email that contains a virus. At that point, the ransomware software is installed and begins blocking the user from using their computer and sometimes shared drive files. After blocking/encrypting the data, the ransomware displays a message on the infected machine. The message explains what has occurred and how to pay the attackers. If the victims pay, the ransomware promises they’ll get a code to unlock their data.
How can I recognize a phishing email?
There are several details that can help a person to recognize a phishing email. No two phishing attempts are quite the same though, so specific details that help you recognize one phishing attempt may not aid you in recognizing another. The following are some common clues that will help you identify a phishing attempt.
Bad grammar and misspellings
Check the email for bad grammar and misspelled words. Sometimes links and domains will even be misspelled but try to mimic a legitimate name. For example, "microsfrtonline.com" instead of "microsoftonline.com".
The message is sent from an unrecognized domain
Check the sender field and see what is after the @. If it looks "phishy" it probably is. Southgate emails end in @sgate.k12.mi.us or @student.sgate.k12.mi.us. Many attempts will come from a public domain, such as @gmail, @outlook, @hotmail, etc. Take a look at the image below. This email clearly did not come from PayPal.
The email includes suspicious links or attachments
Hover over links in emails to check the validity. Phishing emails will often contain a disguised link to lead you to a fraudulent page where the attacker can collect information about you. Emails will sometimes contain attachments that may put malware or other harmful programs on your computer. You may just think an attachment or link is broken, but behind the scenes you could be installing malicious software.
The message creates a sense of urgency
Receiving an email that seems to give us important information or a task that needs to be taken care of quickly is an easy way for the receiver to skip over the details and jump straight into clicking a link.
Let's talk about passwords
Most people use the same password for almost everything, and this is extremely dangerous. If your information gets compromised on one site, then everywhere else you use that password is also at risk. There is a wonderful site called "have I been pwned" where you can search your passwords to see if they have been included in any data breaches.
Here are some good password practices from the Cybersecurity and Infrastructure Security Agency (CISA):
-
Use multi-factor authentication when available.
-
Use different passwords on different systems and accounts.
-
Don't use passwords that are based on personal information that can be easily accessed or guessed.
-
The longer the password the better!
What should I do if I think I have received a phishing email?
Don't open it! You should mark the email as phishing/spam, delete it, and contact the technology department. If you do open it, do not click any links or download any attachments.
If you ever have questions, please contact the Technology Department!
Phone: (734) 246-4648 or Ext. 8300
You can also put in a ticket or come to our office at the high school.
