SFU Mail - Identify and Report Phishing Emails

 

OVERVIEW

This article explains how to identify, protect yourself from, and report phishing emails. Phishing emails attempt to steal passwords and other sensitive information. SFU will never ask you to provide or confirm your Computing ID password by email.

 

What you'll need

  • Access to the suspicious email
  • Access to Outlook on the web (outlook.office.com) or Outlook for mobile

 

Steps to identify a phishing email

SFU, like many other universities, is the subject of "phishing" attacks. Phishing is an attempt to acquire sensitive personal information, such as usernames, passwords and banking information by masquerading as a trustworthy party in an electronic communication. Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website or in a email reply.

The term phishing is a variant of fishing and alludes to the use of increasingly sophisticated baits used in the hope of a "catch" of personal information.

 

SPOTTING A PHISHING ATTEMPT

Uploaded Image (Thumbnail)Above is an example of a phishing attempt sent from a compromised SFU account.

1. The Sender

The Sender: The contents of the email message should match who sent the email. Also, be sure that the email ends with "@sfu.ca". As an example, IT related messages should come from an SFU IT staff or role account that ends with "@sfu.ca".

Ask yourself, does it make sense for this individual to send the contents in the email message and was this sent from an SFU email? In this example, a student account was sending this message on assistance programs which should raise some red flags.

2. Format or layout

Format or Layout: Official SFU messages put in considerable effort not appear like phishing email. This includes introductions, additional context and support points, proper use of SFU logos, fonts, highlights and punctuation.

 Ask yourself, does this message contain sufficient information and proper use of formatting? In this example, there is insufficient context around why you are eligible, and odd usages of SFU logo and punctuations.

3. Honeypot or Threatening Language

Honeypot or Threatening Language: Phishing emails tend to include language that incentives or threatens the user to take urgent action before a deadline, whether it may be a reward or consequence.

Ask yourself, is this too good (or bad) to be true and if I'm being rushed? In this example, it attempts to bait users to provide their information for financial incentives.

4. Grammar Errors or Awkward Phrasing

Grammar Errors or Awkward Phrasing: Similar to Point #2, official SFU messages put in considerable effort to ensure that there are no grammar errors or awkward phrasing. Although mistakes may happen, a significant number of typos, grammar errors or awkward phrasing can indicate phishing attempts if there are call to actions.

Ask yourself, are there typos, grammar errors or awkward phrasing in the email message? In this example, there are many incorrect usage of punctuations and awkward phrasing.

5. External Links or Suspicious Attachments

External Links or Suspicious Attachments: Official SFU messages make a conscious effort to let readers know where links will take them and if there are any attachments. Any form links should point to an SFU service, such as SFU's Microsoft Form or SurveyMonkey.

For attachments, in most cases, they should be office files, .docx, .xlsx, .pdf, .pptx. Be wary of any non-office files, unless you're expecting it to be.

Ask yourself, does this link take me to website I've never seen before? Or, am I being asked to open an attachment I wasn't expecting? In this example, the phishing message is attempting to persuade users to go to an unknown webform and fill out their personal information.

6. Odd sign off and signature

Odd Sign Off and Signature: The signature of the email message should match who (the account) is sending the email. Similar to Point #2, the sign off should be professionally written and formatted.

Ask yourself, does the signature look strange and does it match with the sender? In this example, the sign off does not match the sender. Additionally, the signature does not look professional.

 

Steps to protect yourself from phishing

  • Never provide your Computing ID or password in an email.
  • Don't reply to suspicious emails.
  • Don't click suspicious links or open unexpected attachments.
  • Report suspicious emails using the methods described below.
  • Enable multi-factor authentication (MFA) for additional protection.

 

Steps to report phishing

Easiest and best methods to report phishing

Outlook on the web and Outlook mobile include a built-in Report Phishing button that automatically sends the information needed by SFU's security team and Microsoft to investigate and take action.

 

Outlook on the web

  1. Sign into Outlook on the web
  2. Select the phishing message from the inbox.
  3. Select Report > Report Phishing.Report Phishing OWA

 

Outlook for mobile (iPhone and Android)

  1. Select the email you want to report.
  2. Select ...
    Elipses button highlighted in menu bar
  3. Select Report Phishing

 

 

Advanced method to report phishing

Retrieve and forward email headers on Outlook for Desktop (PC)

OUTLOOK ON DESKTOP

  1. Double-click the email message from your inbox to pop-out the message.Uploaded Image (Thumbnail)
     
  2. Select Files > Properties.
    Uploaded Image (Thumbnail) Uploaded Image (Thumbnail)  
  3. On the Internet Headers box, Right-Click > Select All, then Right Click > Copy to copy the entire message header.Uploaded Image (Thumbnail)
     
  4. Go back to the phishing message and select Forward.Uploaded Image (Thumbnail)
     
  5. On the Message Field, Right-Click > Paste to paste the entire message header.Uploaded Image (Thumbnail)
     
  6. On the To Field, enter abuse@sfu.ca. Then, select Send.Uploaded Image (Thumbnail)

 

Why do I need to include message headers?
Message headers contain technical information about how an email was delivered. They help SFU administrators investigate suspicious messages and identify phishing campaigns. If your email app includes a Report Phishing button, you generally do not need to manually collect headers. If a Report Phishing button is not available, include the message headers when forwarding the email to abuse@sfu.ca.

 

What to expect

After you report a phishing email, SFU administrators review the report and may take additional steps to protect the SFU community from similar messages.

 

If something goes wrong

I clicked a link or provided my password

  1. Close the website.
  2. If you entered your password, change it immediately.
  3. Report the email.

Contact IT Services if you suspect your device or account has been compromised. Enable multi-factor authentication (MFA) for additional protection.

 

I opened an attachment

  1. Close the attachment immediately.
  2. Do not enable macros, content, or permissions if prompted.
  3. Report the email as phishing.
  4. Contact IT Services if the attachment launched software, requested information, or your device begins behaving unexpectedly.

 

My account is locked

Contact IT Services by phone or in-person.

 

I accidentally reported the wrong email

Contact abuse@sfu.ca for assistance in reversing or correcting the report.

 

I suspect my account is compromised or have other security concerns

Contact abuse@sfu.ca for assistance from our team.

Print Article

Related Services / Offerings (1)

SFU mail is the emailing system at SFU for all SFU members.