Protect Yourself From Phishing

Never automatically trust an email simply because you recognize the sender. Malicious emails often have the sending address “spoofed” to make them appear legitimate.

For more information about phishing see our knowledge base!

Look for Warning Signs

Watch for these warning signs to help you identify a phishing email.

  • Spoofed email addresses. A spoofed email address is where the sender name looks legitimate but the full email address either looks “off”, or completely different.
    For example:
  • Spoofed emails are often accompanied by an urgent request for personal or financial information.
  • Emails with generic greetings like “Dear UWSP Email User” asking you to do something.
  • Emails from a sender you may recognize but the sender request or accompanying attachments or links are not expected behavior.

If an email is suspicious in any way, you should verify the email’s legitimacy before interacting further with the email.

If you suspect the email is a phishing attempt, forward the email as an attachment to phishing@uwsp.edu.

Verify an Email’s Legitimacy

To verify an email’s legitimacy, DO NOT use any contact information provided in the email such as phone numbers, email addresses, or available links.​ Contact information provided in a phishing email will always take you to the scammers.

Instead, do one of the following to contact the email sender and ​​ask if they sent the email.

  • Use the phone number saved in your contacts to call the sender (e.g. a different UWSP department, your vendor, bank, or credit card company).
  • Do a web search for the company to find their contact information.
  • If the email is from UWSP, look the sender up in Teams Calls and call them, or email them using their email address from your Outlook Address book.

If you suspect an email is a phishing attempt, forward the email as an attachment to phishing@uwsp.edu.

See additional information from the Better Business Bureau on How to recognize a phony email.

If You Suspect Your Account is Compromised

If you suspect your account has been compromised, contact the IT Service Desk immediately. If after hours, you should also email the Information Security Office.

DO NOT use Microsoft Outlook’s built in Report tool to report a phishing attempt. The Report tool should only be used to report spam. See How do I Report an Email as Phishing or Spam? to learn more.

Always practice good email security habits

Always practice the following additional good email security habits to help protect your account, and UWSP’s network and secure data.

  • DO NOT email personal information (such as a password, credit card number, Social Security Number, birthday, etc).
  • DO NOT click on links, or any active content in a suspicious email. Links can be hidden, misleading, or lead to sites that automatically install viruses or trojans.
  • DO NOT reply to a suspicious email, open any attachments, or use included phone numbers. All contact options in a phishing email lead back to the scammer.
  • Do NOT use “personal” e-mail addresses like those available through Gmail, Yahoo, etc. for university business. The Family Educational Rights and Privacy Act (FERPA) requires institutions to maintain control over education records.
    Use of a personal external email:
    • Can violate this requirement if records are stored or transmitted outside institutional systems.
    • May be considered an unauthorized disclosure if data is exposed.
  • Keep your university work and personal life (including passwords, emails, etc) separate so that if one account is breeched, the other remains safe.

And don’t forget your personal computers

You should similarly protect all personal computers at your home by doing the following:

  • Always keep your web browsers up-to-date with the latest security patches.
  • Always make sure that you have good, up-to-date antivirus software that includes spyware protection.
  • See the Federal Trade Commission’s page on Identity Theft for more information on how to protect yourself and your family.