Don't take the bait – be aware of phishers!
Phishing is the act of tricking you into giving away sensitive information or downloading malicious software onto your computer or our network. The University is regularly targeted by such attacks.
The potential impact of these attacks on organisations can be considerable, including financial loss, personal and business data leaks, IT network outages, reputational damage and even fines from the Information Commissioner's Office (ICO).
We've shared some top tips for spotting phishing emails below, but if you've clicked a link or engaged with a suspicious email, we need to know immediately to protect your data and the University. Even if you are in doubt, please don't hesitate to contact the IT Services Helpdesk on 024 765 73737. We'd rather tell you the email is genuine than you fall for a scam.
On our Data Incidents and Breaches webpageLink opens in a new window, you'll find guidance for reporting data breaches, including an online form.
Top tips: Stay safe from phishing
Help us protect your and the University's data by looking for the most commonly deployed phishing techniques.
Is it an unexpected email? 
If you receive an email you aren't expecting or are unsure where it originated, you should take some time to think and look through the content before you reply or open any links or attachments. 
You didn't initiate the action
If you get a message informing you that you have won a contest you did not enter or that your parcel from somewhere you didn't order from is ready for delivery, alarm bells should be ringing.
Is it too good to be true?
An email giving you a fantastic offer on a new phone, or saying you've won something in a competition you've never entered, is unlikely to be genuine. 
The email contains poor spelling and grammar
Phishing emails are translated into many different languages and often feature incorrect spelling and grammar, for example, "I hope you can this messege without effort!".
The email indicates urgent action is required
Scams often send an email as "Action Required" to hurry you to reply without making any checks. They can even be designed to scare you, for example, "Act now or your account will be deleted!" 
The email address looks suspicious
Hover over the name to see the full email address - the name displayed might look okay, but does it match the email address? For example, an email address displayed as "Microsoft Support" looks plausible, but you should reconsider if it comes from happy123@dodgy.com.
The email contains a link
If the email contains links, hover over them with your mouse first (do not click). Does the preview web link (URL) appear to match the link in the email text? If it doesn't, you may have found a phish. 
There's a handy link to login to your account
Phishers want to make it easy for you to give them your details. If you are unsure if an email is genuine, go to the company website and log in to your account. 
The email asks for personal information
A reputable company should never send an email asking for your password, bank card number, or the answer to a security question. If you know the company, check with them via another route (phone or email separately).