What does a phishing email look like?
Phishing emails can take various forms, and scammers are always evolving their methods to trick you. However, most attacks rely on a few common strategy types:
1. "CEO Fraud" / Authority Impersonation
What it looks like: The scammer pretends to be your boss, a campus VP, a dean, or another high-ranking Geneseo individual. The initial email often contains no links or attachments—just a brief message like "Are you at your desk?" or "I need a quick favor." It usually includes a reason why they can't talk on the phone, such as "I’m in an important meeting" or "About to board a plane."
What it's trying to do: They exploit your natural desire to respond quickly to authority figures without over-scrutinizing the request. Once you reply, they will ask you to perform an urgent task, like purchasing gift cards, initiating a wire transfer, or sending over sensitive documents (like W-2s or health records).
2. Business Email Compromise (BEC)
What it looks like: These messages typically appear to come from an acquaintance, vendor, or a colleague outside Geneseo. They often feature subject lines like "[Name] has shared a document with you" and perfectly mimic official notification emails from Google Drive, OneDrive, or Dropbox.
What it's trying to do: They rely on existing professional relationships. If you have exchanged files with this person in the past, you are likely to trust the notification. Clicking the link takes you to a fake login page designed specifically to harvest and steal your password.
3. IT Support Spoofing
What it looks like: The sender pretends to be from CIT, Google Support, or Microsoft Security. They rely heavily on alarming words like "Urgent," "Account Blocked," or "Security Alert" and reference your email quota or voicemail inbox.
What it's trying to do: They want to induce panic so you act before thinking. They may claim your mailbox is full, your password was leaked, or your account will be deleted in 24 hours unless you click a link to "verify" your identity.
Spotting a Suspicious Email
If you feel uncertain about a message, trust your instincts and verify it safely using these steps:
- View it directly in Gmail: If you typically read mail through a desktop or mobile client (like Apple Mail, Outlook, or Thunderbird), log into your account using a web browser at gmail.com. Google frequently displays contextual security warnings or banners on malicious emails that third-party apps fail to show.
- Verify via a separate channel: If an email appears to come from a colleague or friend but feels out of character, contact them using a completely different method. Call or text them using a phone number you already know is correct. Never use a phone number listed in the suspicious email's signature, as that could be fake too.
- Ask a colleague: Show the email to a coworker. Does it look suspicious to them? If the message concerns a shared project or campus department, your colleagues can help verify if the request makes sense.
Reporting an Email
You should always use the native tools built directly into Gmail to flag suspicious messages.
To report an email, click the three vertical dots (More Options) located right next to the reply arrow on the message pane.


Should I choose "Report Spam" or "Report Phishing"?
⚠️
If you are unsure as to which report function is most appropriate, use "report spam."
| Use Report Spam if the email is: |
Use Report Phishing if the email is: |
- Unsolicited marketing or sales pitches
- Generic newsletters you didn't subscribe to
- Random nonsense or digital junk mail
|
- Impersonating a Geneseo college official
- Referencing an unexpected shared document link
- Demanding you click a link to verify your password
- Using urgent threats to force you to open an attachment
|
💡 Mobile Tip: If the "Report Phishing" option is missing on your mobile device or mail app, use Report Spam for all suspicious messages.
I Responded to a Phishing Email
If you realized too late that you interacted with a phishing email, don't panic, and do not feel embarrassed. Cyberattacks are highly sophisticated, and it happens to almost everyone eventually.
- Opening the email is usually fine: In 99% of cases, simply clicking on an email to read it will not harm your device or account. The danger comes from secondary interactions: clicking links, downloading attachments, replying to the sender, or entering your password.
- Do not delete anything: Your natural instinct might be to delete the files or emails to "undo" the mistake. Please leave them exactly where they are. CIT's security team may need to inspect the message headers or files to protect your account and the rest of the campus.
- Report it immediately: Reach out to the HelpDesk right away. Being completely honest about what links you clicked or what forms you filled out is the single best way to minimize damage and secure your digital identity.