Mail is sometimes received by students and staff from fraudulent sources trying to extract private information. We already take action to reduce the number of these, but you still need to be vigilant. If you are not expecting an email, or are suspicious of its content, do not click on any links. Check with the sender separately to make sure it is a genuine message.
Key signs of phishing and scam emails
- Too good to be true: Attention-grabbing statements or offers designed to lure you.
- Demanding action: Emails asking you to act quickly, e.g., to claim a prize or prevent account termination.
- Suspicious hyperlinks: Hover over links to check the true destination; do not click unexpected links.
- Unexpected attachments: Do not open attachments you weren’t expecting.
- Unusual sender: Even if it looks like it’s from someone you know, exercise caution. Contact the sender separately to the email to check if they sent you it.
- Requests for personal information: Legitimate emails will never ask for passwords or sensitive data.
- Unexpected actions: If unsure, go directly to the organisation’s website rather than using links in an email.
- Something doesn’t feel right: Delete suspicious emails and report internal phishing attempts immediately.
Advice regarding suspect mail
- Never send your ucreative password via email: we will never request you to do so.
- Do not click links in emails unless you are 100% sure they are legitimate.
- Delete suspect messages immediately: never reply to mail from unknown sources or suspected malicious mail.
- Do not expand an email: If an email asks you to click on a link to expand the view, do not click on the link and delete the email.
- Do not click on any SharePoint links if you are not expecting a document from the sender.
- Don’t just trust the sender: Some phishing emails may appear to come from legitimate Microsoft addresses, such as no-reply@sharepointonline.com
If you have accidentally clicked on any suspicious email link
- Change your password immediately.
- Scan the device you were using for malware.
- Do not accept MFA requests that you didn’t initiate.
- Check you have no new Rules set up in your email (see ‘How do I check for Rules?’)
- If the email was sent to your UCA email address, report the email to: StudentITSupport@uca.ac.uk
