What is Phishing?
Phishing is a type of cyberattack where criminals disguise themselves as a trusted institution or official entity to steal your sensitive data. Their primary goal is usually identity theft or financial fraud. They attempt to trick you into:
-
Revealing credentials (passwords, usernames).
-
Sharing personal identifiers (Social Security numbers, dates of birth).
-
Providing financial access (credit card numbers, wire transfers, or purchasing gift cards).
While email is the most frequent avenue - targeting Geneseo users almost daily - phishing can also happen over text messages (smishing) or phone calls (vishing). These malicious messages are often carefully crafted to look exactly like official communications from campus departments (such as Human Resources or CIT) or government entities (like NYS or the IRS).
How to Guard Against Phishing
Protecting your information requires a healthy dose of skepticism. Follow these core safety rules:
-
Never share passwords via email: No reputable organization - including CIT - will ever ask you to reply to an email with your password or full sensitive details.
-
Verify phone callers: If someone calls claiming to represent an official organization and requests personal details, hang up. Look up the organization’s publicly listed phone number independently and call them back.
-
Inspect email senders closely: Do not trust the "Display Name" (the text name showing who sent the message). Always look closely at the actual email address listed inside the angle brackets < >.
-
Hover before you click: Links in emails can easily be masked to display a legitimate web address while actually routing you to a malicious site. Hover your mouse over any link to preview the actual destination URL before clicking.
-
Double-check browser addresses: If you do open a link, inspect the browser's address bar carefully. Phishers are adept at registering domain names that mimic official brands by changing just one or two letters.
How to Protect the SUNY Geneseo Community
CIT tracks and posts active email threats on The Phish Bowl site.
You play a vital role in keeping our campus secure - if you spot a suspicious email, please take one of the following actions to report it:
| Situation |
Action to Take |
|
You spot a suspicious message (not on The Phish Bowl site)
|
Report it in Gmail:
|
| You have a strange message and want to ask a question |
Forward it to CIT: Unsure if a message is safe? Send it to our security team for review. For the best analysis, forward the suspicious message to citsd@geneseo.edu. |
❌
Above all: when in doubt, do not interact. Never reply to a suspicious message, download its attachments, or enter your credentials into any linked form.