
OVERVIEW
This article explains how to identify, protect yourself from, and report phishing emails. Phishing emails attempt to steal passwords and other sensitive information. SFU will never ask you to provide or confirm your Computing ID password by email.
What you'll need
- Access to the suspicious email
- Access to Outlook on the web (outlook.office.com) or Outlook for mobile
Steps to identify a phishing email
SFU, like many other universities, is the subject of "phishing" attacks. Phishing is an attempt to acquire sensitive personal information, such as usernames, passwords and banking information by masquerading as a trustworthy party in an electronic communication. Phishing is typically carried out by email or instant messaging and often directs users to enter details at a website or in a email reply.
The term phishing is a variant of fishing and alludes to the use of increasingly sophisticated baits used in the hope of a "catch" of personal information.
SPOTTING A PHISHING ATTEMPT
Above is an example of a phishing attempt sent from a compromised SFU account.
1. The Sender
The Sender: The contents of the email message should match who sent the email. Also, be sure that the email ends with "@sfu.ca". As an example, IT related messages should come from an SFU IT staff or role account that ends with "@sfu.ca".
Ask yourself, does it make sense for this individual to send the contents in the email message and was this sent from an SFU email? In this example, a student account was sending this message on assistance programs which should raise some red flags.
2. Format or layout
Format or Layout: Official SFU messages put in considerable effort not appear like phishing email. This includes introductions, additional context and support points, proper use of SFU logos, fonts, highlights and punctuation.
Ask yourself, does this message contain sufficient information and proper use of formatting? In this example, there is insufficient context around why you are eligible, and odd usages of SFU logo and punctuations.
3. Honeypot or Threatening Language
Honeypot or Threatening Language: Phishing emails tend to include language that incentives or threatens the user to take urgent action before a deadline, whether it may be a reward or consequence.
Ask yourself, is this too good (or bad) to be true and if I'm being rushed? In this example, it attempts to bait users to provide their information for financial incentives.
4. Grammar Errors or Awkward Phrasing
Grammar Errors or Awkward Phrasing: Similar to Point #2, official SFU messages put in considerable effort to ensure that there are no grammar errors or awkward phrasing. Although mistakes may happen, a significant number of typos, grammar errors or awkward phrasing can indicate phishing attempts if there are call to actions.
Ask yourself, are there typos, grammar errors or awkward phrasing in the email message? In this example, there are many incorrect usage of punctuations and awkward phrasing.
5. External Links or Suspicious Attachments
External Links or Suspicious Attachments: Official SFU messages make a conscious effort to let readers know where links will take them and if there are any attachments. Any form links should point to an SFU service, such as SFU's Microsoft Form or SurveyMonkey.
For attachments, in most cases, they should be office files, .docx, .xlsx, .pdf, .pptx. Be wary of any non-office files, unless you're expecting it to be.
Ask yourself, does this link take me to website I've never seen before? Or, am I being asked to open an attachment I wasn't expecting? In this example, the phishing message is attempting to persuade users to go to an unknown webform and fill out their personal information.
6. Odd sign off and signature
Odd Sign Off and Signature: The signature of the email message should match who (the account) is sending the email. Similar to Point #2, the sign off should be professionally written and formatted.
Ask yourself, does the signature look strange and does it match with the sender? In this example, the sign off does not match the sender. Additionally, the signature does not look professional.
Steps to protect yourself from phishing
- Never provide your Computing ID or password in an email.
- Don't reply to suspicious emails.
- Don't click suspicious links or open unexpected attachments.
- Report suspicious emails using the methods described below.
- Enable multi-factor authentication (MFA) for additional protection.
Steps to report phishing
Easiest and best methods to report phishing
Outlook on the web and Outlook mobile include a built-in Report Phishing button that automatically sends the information needed by SFU's security team and Microsoft to investigate and take action.
Outlook on the web
- Sign into Outlook on the web
- Select the phishing message from the inbox.
- Select Report > Report Phishing.

Outlook for mobile (iPhone and Android)
- Select the email you want to report.
- Select ...

- Select Report Phishing
Note: While newer versions of Outlook for desktop also support this feature, they are not yet widely available on campus computers. As a result, we recommend using the Outlook on the web or mobile reporting methods whenever possible.
Advanced method to report phishing
Retrieve and forward email headers on Outlook for Desktop (PC)
What to expect
After you report a phishing email, SFU administrators review the report and may take additional steps to protect the SFU community from similar messages.
If something goes wrong
I clicked a link or provided my password
- Close the website.
- If you entered your password, change it immediately.
- Report the email.
Contact IT Services if you suspect your device or account has been compromised. Enable multi-factor authentication (MFA) for additional protection.
I opened an attachment
- Close the attachment immediately.
- Do not enable macros, content, or permissions if prompted.
- Report the email as phishing.
- Contact IT Services if the attachment launched software, requested information, or your device begins behaving unexpectedly.
My account is locked
Contact IT Services by phone or in-person.
I accidentally reported the wrong email
Contact abuse@sfu.ca for assistance in reversing or correcting the report.
I suspect my account is compromised or have other security concerns
Contact abuse@sfu.ca for assistance from our team.