Skip to main content
NC State Home
Cybersecurity

Fall Semester Phishing Tips

Decorative

Don’t fall for phishing this semester.

Phishing might look like an unexpected email, a text with a malicious link or a fake website requesting personal information. And one wrong click or share puts our entire community’s data at risk.

Always remember these three steps:

  1. Be suspicious.
  2. Take your time.
  3. Ask for help.

What the Scammers Are Saying

  • “Your account will be deactivated.”
  • “You have a new document for electronic review.”
  • “New work study opportunities”
  • “Personalized compensation statement”

While artificial intelligence is making phishing more sophisticated, there are still some red flags that can help you spot a scam. Look out for:

  • A sense of urgency
  • Unexpected messages
  • Offers that are too good to be true
  • Generic language

Stay Safe With These Tips

Verify the Sender

Is that email really from the chancellor? Many phishing emails impersonate university officials. Always verify the email sender’s address, even if it seems familiar. If the email appears to be from someone you know personally, contact them in a different way.

A gif shows a phishing email that appears to come from the chancellor. The gif then says, "Think you know the sender? Think again. Verify the email address."

Hover Over Links

Malicious links are often disguised to look legitimate. Always hover over hyperlinked text — or carefully press and hold on a mobile device — to see where it points. If the destination is unclear, it may be a scam. When in doubt, don’t click.

A gif shows a phishing email with a malicious link disguised as real. The gif then says, "Links might not lead where you expect. Before you click, check the destination."

Check Login Page URLs

Our community often encounters phishing scams that involve fake login pages. As NC State’s login experience gradually transitions from Shibboleth to Entra ID this fall, it’s extra important to pay attention to URLs before logging in to university systems. You will see both Shibboleth and Entra login pages over the next few months.

  • An Entra login page’s URL will always start with login.microsoftonline.com.
  • A Shibboleth login page’s URL will always start with shib.ncsu.edu.

Report Phishing

If you suspect phishing, do not reply or forward the email. Report it immediately.

For monthly tips to help you stay safe online, subscribe to OIT News. Learn more about phishing.