Scams, Spam & Malware

Mail is sometimes received by students and staff from fraudulent sources trying to extract private information. We already take action to reduce the number of these, but you still need to be vigilant. If you are not expecting an email, or are suspicious of its content, do not click on any links. Check with the sender separately to make sure it is a genuine message.

Key signs of phishing and scam emails

  • Too good to be true: Attention-grabbing statements or offers designed to lure you.
  • Demanding action: Emails asking you to act quickly, e.g., to claim a prize or prevent account termination.
  • Suspicious hyperlinks: Hover over links to check the true destination; do not click unexpected links.
  • Unexpected attachments: Do not open attachments you weren’t expecting.
  • Unusual sender: Even if it looks like it’s from someone you know, exercise caution. Contact the sender separately to the email to check if they sent you it.
  • Requests for personal information: Legitimate emails will never ask for passwords or sensitive data.
  • Unexpected actions: If unsure, go directly to the organisation’s website rather than using links in an email.
  • Something doesn’t feel right: Delete suspicious emails and report internal phishing attempts immediately.

Advice regarding suspect mail

  • Never send your ucreative password via email: we will never request you to do so.
  • Do not click links in emails unless you are 100% sure they are legitimate.
  • Delete suspect messages immediately: never reply to mail from unknown sources or suspected malicious mail.
  • Do not expand an email: If an email asks you to click on a link to expand the view, do not click on the link and delete the email.
  • Do not click on any SharePoint links if you are not expecting a document from the sender.
  • Don’t just trust the sender: Some phishing emails may appear to come from legitimate Microsoft addresses, such as no-reply@sharepointonline.com

If you have accidentally clicked on any suspicious email link

  • Change your password immediately.
  • Scan the device you were using for malware.
  • Do not accept MFA requests that you didn’t initiate.
  • Check you have no new Rules set up in your email (see ‘How do I check for Rules?’)
  • If the email was sent to your UCA email address, report the email to: StudentITSupport@uca.ac.uk

 

FAQs

  • I received an email which looks suspicious, what should I do?

    Do not click on any links or attachments. If you are sure that it is a spam email, delete is straight away, if you are not sure and know who it is supposed to be from, contact them separately to check if it is legitimate.

  • I keep getting requests for a code when I didn’t log in.

    Firstly, don’t panic and don’t accept the request.

    Check if you are signed into any UCA accounts on any device and sign out. This might simply be a device you have remained logged into trying to connect.

    If you are not logged into any UCA accounts, or you continue to receive these requests after you have signed out, reset your password and scan the devices on which you were signed in.

  • I got an email which tells me my account is compromised, is it real?

    These emails should be from studentITsupport@uca.ac.uk, if it is, it mentions your name, it is likely to be genuine.

    If you are unsure, please contact the IT Advisors for confirmation:

    Email: studentITsupport@uca.ac.uk or call 01252 918 504

  • My friends have said that I am emailing them from my university account when I’m not, what should I do?
    • Make sure you change your UCA password as soon as possible in case your account has been compromised.
    • Run a virus scan on all devices on which you have used your UCA account.
    • Check you have no Rules set up in your email (see ‘How do I check for Rules?’)
    • Tell your friends not to open any of these emails and to delete them. If they have opened the emails and clicked on a link, they will need to follow the steps above.
  • How do I check for Rules?

    Check if your emails are going straight into the Junk email. If they are, you may have had a virus which set up a rule to send them there.

    To check your Rules:

    Windows App – File > Manage Rules and Alerts
    Apple App – Outlook > Apply Rule > Edit Rule
    Mobile App - Settings > Mail > Rules
    Webmail – File > Email > Rules

    Delete any Rule you don’t recognise. If there is a Rule, once deleted, we recommend you reset your UCA password and run a virus scan any device on which you have used your account.

  • Does UCA protect my account?

    There are detection systems in place on UCA accounts, which will flag any suspicious behaviour on your UCA email account, or your device while it is connected to the Eduroam network.

    These include spam emails, multiple sign-in attempts in different locations, cryptocurrency mining attempts or malware detection. If your account or device is flagged by these systems, it will be locked, and you will be contacted by the Student IT Support team. Please follow the instructions on this email to reactivate your account. 

  • Recommended Antivirus Software

    It is recommended that antivirus software is installed on your computer. If you do not have one, UCA can recommend either Sophos Home or Malware Bytes. Both have free versions available that provide basic protection.