Protect Yourself from Phishing and Cyber Threats

Cybercriminals target colleges and universities because campus communities combine valuable information, financial transactions, research, technology systems, and thousands of user accounts.

At CSUN, phishing may arrive through email, text messages, QR codes, phone calls, shared documents, collaboration tools, social media, or fake websites. Attackers may impersonate CSUN leaders, faculty, staff, students, vendors, financial institutions, or technology services.

Modern phishing messages can look professional and may even come from a legitimate CSUN account that has been compromised. Do not rely on spelling mistakes or poor grammar alone to decide whether a message is safe.

Think before you click, scan, approve, send, or pay.

Received something suspicious?
Do not click links, open attachments, scan QR codes, reply, send money, or approve an unexpected Duo/MFA request.
Report suspicious email to abuse@csun.edu.


Stop. Check. Report.

When a message asks you to take an unexpected action:

1. Stop

Do not immediately follow the instructions in the message, especially when it creates urgency or pressure.

2. Check

Verify the request using a trusted method that you already know.

For example:

  • Go directly to the CSUN website or service instead of using a link in the message.
  • Contact the person or department using contact information from the CSUN directory or an official webpage.
  • Check the complete sender address, not just the displayed name.
  • Confirm unexpected requests for payments, gift cards, account changes, sensitive information, or Duo/MFA approvals.
3. Report

Send suspected phishing messages to abuse@csun.edu. When possible, send the suspicious email as an attachment so Information Security or IT Help Center can review the original message information and headers.


Common Cyber Threats at Colleges and Universities

Fake Job and Internship Offers

Students are frequently targeted with messages advertising remote jobs, internships, research assistant positions, mystery shopper opportunities, or other unusually flexible and high-paying work.

Warning signs include:

  • You did not apply for the position.
  • A professor, administrator, or executive unexpectedly offers you a job.
  • The sender moves the conversation to text or a personal email account.
  • You are asked to purchase equipment, gift cards, or supplies.
  • You receive a check and are asked to send part of the money elsewhere.
  • You must pay a fee before you can begin working.
  • The employer asks for banking or personal information before normal hiring paperwork is completed.

Legitimate internships and jobs should not require you to send money to receive employment.


Protect Your CSUN Account

A few habits can significantly reduce your risk.

Use MFA Carefully

Multi-factor authentication adds an important layer of security.

  • Never approve an authentication request you did not initiate.
  • Never share an MFA or verification code.
  • Review the service requesting authentication before approving it.
  • Use the strongest authentication methods available to you.
Protect Your Password
  • Never send your CSUN password through email, text, or a form sent to you unexpectedly.
  • Use a unique password for your CSUN account.
  • Do not reuse your CSUN password on personal websites or services.
  • If you believe your password has been exposed, change it immediately.
Keep Devices Updated

Install operating system, browser, application, and security updates promptly.

Updates frequently correct security vulnerabilities that attackers can exploit.

Protect University and Personal Information

Before sharing sensitive information, confirm:

  • Who is requesting it
  • Why they need it
  • Whether they are authorized to receive it
  • Whether you are using an approved method to transmit it

Be especially careful with student records, employee information, research data, financial information, credentials, and other protected university data.


How to Recognize a Suspicious Message

No single warning sign proves that a message is phishing. Instead, look at the message as a whole.

Be cautious when a message:

  • Creates unusual urgency, fear, or pressure.
  • Threatens to close, suspend, or restrict your account.
  • Requests your password, authentication code, Social Security number, banking information, or other sensitive information.
  • Asks you to approve an unexpected Duo/MFA notification.
  • Asks you to scan a QR code to verify an account.
  • Requests gift cards, cryptocurrency, wire transfers, or unexpected payments.
  • Offers a job or internship that seems unusually easy or lucrative.
  • Asks you to move a conversation from CSUN email to text or a personal account.
  • Contains a link that leads somewhere different from where you expected.
  • Uses an unexpected sender address or domain.
  • Requests secrecy or asks you to bypass normal university procedures.
  • Requires you to open an unexpected attachment or shared document.
  • Involves a change to payroll, direct deposit, vendor payment, or banking information.
  • Asks you to act on something you did not initiate.

Remember: a familiar name or CSUN email address does not guarantee that the message is legitimate. Accounts can be compromised and display names can be impersonated.


Protect Your CSUN Account

A few habits can significantly reduce your risk.

Use MFA Carefully

Multi-factor authentication adds an important layer of security.

  • Never approve an authentication request you did not initiate.
  • Never share an MFA or verification code.
  • Review the service requesting authentication before approving it.
  • Use the strongest authentication methods available to you.
Protect Your Password
  • Never send your CSUN password through email, text, or a form sent to you unexpectedly.
  • Use a unique password for your CSUN account.
  • Do not reuse your CSUN password on personal websites or services.
  • If you believe your password has been exposed, change it immediately.
Keep Devices Updated

Install operating system, browser, application, and security updates promptly.

Updates frequently correct security vulnerabilities that attackers can exploit.

Protect University and Personal Information

Before sharing sensitive information, confirm:

  • Who is requesting it
  • Why they need it
  • Whether they are authorized to receive it
  • Whether you are using an approved method to transmit it

Be especially careful with student records, employee information, research data, financial information, credentials, and other protected university data.


If You Clicked or Responded

Making a report quickly can help limit the impact of an incident.

If you believe you interacted with a phishing message:

  1. Stop interacting with the message or website.
  2. Do not approve any unexpected Duo/MFA requests.
  3. Change your password immediately if you entered it into a suspicious website or provided it to someone.
  4. Report the message to abuse@csun.edu.
  5. Contact CSUN Information Security if you believe your account, computer, or university data may have been compromised.
  6. If money or financial information was involved, contact the appropriate financial institution or university office as soon as possible.

Do not delete the suspicious message until it has been reported if Information Security may need it for investigation.


How to Report Phishing to CSUN

When reporting a suspicious email to abuse@csun.edu, send the original email as an attachment whenever possible.

Sending the message as an attachment preserves information that can help Information Security or IT Help Center investigate the sender, links, routing information, and other indicators associated with the attack.

Information Security
Phone: (818) 677-6100
Email: iso@csun.edu

IT Help Center
Phone: (818) 677-1400
Email: support@csun.edu

For urgent security concerns involving a CSUN account, device, system, or university data, contact Information Security or IT Help Center.


Before You Act, Ask Yourself

Was I expecting this message?

Is the request normal for this person or department?

Am I being pressured to act immediately?

Am I being asked for a password, MFA approval, money, gift cards, or sensitive information?

Can I verify the request another way?

When in doubt, verify first and report suspicious activity.


Phishing Types

Attackers frequently create fake CSUN, Microsoft, Google, Duo, financial aid, library, cloud storage, or other login pages to steal usernames and passwords.

Messages may claim:

  • Your account will be disabled.
  • Your mailbox is over quota.
  • Your password is expiring immediately.
  • A document has been shared with you.
  • You must validate or upgrade your account.
  • Unusual activity was detected.
  • You have a missed voicemail or secure message.
  • Your financial aid or student account requires action.

Instead of using the link in the message, navigate directly to the service through a trusted CSUN webpage or a bookmark you created yourself.

CSUN will never need you to send your password by email.

Multi-factor authentication provides important protection, but attackers may try to trick you into approving their login.

Be suspicious if you receive:

  • A Duo notification you did not initiate.
  • Repeated authentication prompts.
  • A request to provide an MFA code to another person.
  • A QR code claiming that you must “reactivate” or “upgrade” MFA.
  • A phone call or message asking you to approve an authentication request.
  • Instructions to disable or bypass MFA.

Only approve an authentication request when you initiated the login and recognize the service.

If you receive an unexpected Duo/MFA request, deny it and report the activity.

QR phishing, sometimes called quishing, uses a QR code to send you to a malicious website.

QR codes may appear in:

  • Emails
  • Flyers
  • Parking notices
  • Event promotions
  • Fake invoices
  • Account verification messages
  • MFA enrollment instructions

A QR code can hide its destination just as a shortened or disguised web link can.

Before entering a password or other sensitive information after scanning a QR code, verify that the website is the legitimate site you intended to visit.

An attacker may pretend to be a dean, department chair, professor, supervisor, executive, or coworker and ask you to purchase gift cards or make an urgent payment.

A typical message may begin with a simple question such as:

“Are you available?”

The attacker then creates urgency and asks you to buy gift cards, send the card numbers, transfer money, or keep the request confidential.

Before acting on an unusual financial request, verify it with the person through a separate, trusted communication method.

Cybercriminals may impersonate an employee, student, vendor, or university official to redirect money.

Watch for requests involving:

  • Direct-deposit changes
  • Payroll information
  • Refunds
  • Tuition payments
  • Financial aid
  • Scholarships
  • Vendor banking information
  • Wire transfers
  • Invoices
  • Purchasing
  • Tax documents

Faculty and staff who process financial or administrative transactions should independently verify unexpected changes to payment or banking information using established university procedures.

Attackers may send fake notifications that appear to come from Microsoft 365, Google Drive, OneDrive, Dropbox, Adobe, DocuSign, or another collaboration service.

The message may say that a colleague or professor has shared:

  • A document
  • Class materials
  • A contract
  • A voicemail
  • A file requiring a signature
  • A confidential report

A compromised campus account can also be used to send a malicious sharing invitation, making the message appear more trustworthy.

Verify unexpected files or sharing requests before signing in or opening content.

Higher education institutions are attractive targets because of their research, intellectual property, purchasing activity, partnerships, and open collaboration environments.

Faculty, researchers, administrators, and staff should be cautious of unexpected messages involving:

  • Research collaborations
  • Grant opportunities
  • Conference invitations
  • Journal submissions
  • Vendor invoices
  • Contract changes
  • Cloud services
  • Sensitive research data
  • Requests for credentials or file access

Verify unusual requests directly with the organization or individual using independently obtained contact information.

Phishing is not limited to email.

Fraudulent text messages may claim to be from:

  • CSUN
  • A professor or supervisor
  • A delivery company
  • A bank
  • A government agency
  • A financial aid provider
  • A technology support team

Do not trust a message simply because it knows your name, department, job title, or school. Much of this information may be publicly available.

Artificial intelligence can help attackers create messages that are well written, personalized, and convincing.

Attackers may use publicly available information to imitate:

  • A supervisor's writing style
  • A university administrator
  • A professor
  • A classmate or coworker
  • A vendor or business partner

Voice, image, and video impersonation can also be used in fraud.

A message that looks or sounds professional is not automatically trustworthy.

Focus on the request, context, destination, and verification, not just the appearance of the message.


Phishing Examples

See real phishing examples reported by members of the CSUN community and learn what made each message suspicious.

---Start of Email---

From: <xxx.xxxx@gaggle.com>
Date: Mon, Jul 14, 2025 at 10:24 AM
To: <your.email@students.edu>
Subject: CSUN: IT Information Security Advisory Announcements] MFA Authentication

Phishing Email Example

---End of Email---

How do we know it's phishing?

  1. Suspicious Sender: The message is from a personal Gmail account, not an official CSUN email address.
  2. Unsolicited MFA Setup Request: CSUN IT does not typically ask users to submit their phone number or scan QR codes via unsolicited emails.
  3. Lack of Personalization: The message does not address the recipient by name or contain any specific information.
  4. Urgency Without Context: It pressures users to act without providing verification methods or contact details.

What to do if you receive a similar email:

  1. Do Not Scan Any Codes: QR codes in phishing emails can lead to malicious websites or trigger unauthorized actions.
  2. Do Not Respond: Avoid replying to the email or engaging with the sender in any way.
  3. Verify Your Account Security: Change your email password immediately and enable multi-factor authentication (MFA) for added security.
  4. Report the Email: Forward the email to abuse@csun.edu and reach out to Information Security at (818) 677-6100.

---Start of Email---

From: <your.email@students.edu>
Date: Sun, Jan 12, 2025 at 9:25 PM
To: <your.email@students.edu>
Subject: noreply

Hi!

I'm going to make you an offer you can't refuse. If reputation means anything to you.
I am a programmer who likes to dig into other people's dirty laundry and I hack into cell phones, laptops, computers,
tablets of users like you in order to extract from them "interesting" photos, videos, recordings of conversations or correspondence.
I infected your device with a virus and have been watching you for over 2 months now.
During these months, I have accumulated a lot of interesting information about you.

Not only do I have access to your phone book, correspondence, audio, but I also have information about the sites you visit.
Can you guess what I'm talking about?

I collect a selection of photos and videos, audio recordings, correspondence from the devices of users like you with the help of viruses and copy them to my own server.
I've got some bad news for you. I can leak all of this online for general access, send it to your friends, relatives, acquaintances, send it to social networks and messengers.
Trust me. This is something that can destroy your reputation once and for all!
The effect will be fantastic! They will see what you do in all its glory.

It only takes one click for me to leak the information.
You have the power to stop it. What do you have to do to stop it? I'll tell you about that next.

You need to make a $1100 (US dollars) transfer to my bitcoin wallet. If you do not know how such transfers are made, just type in Google query: "Buy Bitcoin".
My bitcoin wallet (BTC Wallet): <removed>

Nothing complicated, right?
After receiving the specified amount, I will immediately delete all the information and leave you alone forever!

But you need to hurry up. I don't like to wait long!
I'll give you 48 hours.

Don't think you can ignore me. After you read this message, I automatically get a notification about it.
From then on, you have two days to pay!

Yes. You don't need to try to apply for help to resolve this situation. Bitcoin wallet is untraceable, and the sender address is automatically created.
But if I happen to know that you share this email with someone else (and I will), I'll do a newsletter right away!
I hope you make the right choice!

---End of Email---

How do we know it's phishing?

Note: The attacker sent the email above using the user's email account, indicating that the attacker has access to the account, which means it has been compromised. However, this situation is still considered phishing due to the following reasons:

  1. Generic Sender Information: The email does not address the recipient by name, making it a generic template.
  2. Threatening Language: The email uses fear tactics and threats to intimidate the recipient into compliance.
  3. Untraceable Payment Request: The demand for Bitcoin payment is a common hallmark of phishing scams, as Bitcoin transactions are difficult to trace.
  4. Unverifiable Claims: The sender claims to have access to personal information but does not provide specific evidence.

What to do if you receive a similar email:

  1. Do Not Respond: Avoid replying to the email or engaging with the sender in any way.
  2. Verify Your Account Security: Change your email password immediately and enable multi-factor authentication (MFA) for added security.
  3. Report the Email: Forward the email to abuse@csun.edu and reach out to Information Security at (818) 677-6100.
  4. Do Not Click Links or Pay: Avoid clicking on any links in the email and do not send money or Bitcoin.

Examples from previous years can be found below: