Phishing is when a scammer uses fraudulent emails or texts, or copycat websites to get you to share valuable personal information –such as account numbers, social security numbers, or your login IDs and passwords. Scammers use your information to steal your money, your identity or both.
Scammers also use phishing emails to gain access to your computer or network, and then they install programs like ransomware that can lock you out of important files on your computer.
This page provides examples of the phishing emails received by the campus community at large. Each example includes the actual text used to lure the user into a false sense of security and points out why the email is suspicious. Please use these examples to educate yourself on what to look for so that you do not become a victim.
GIFT CARD SCAMS
Gift cards have become a popular way for scammers to steal your money. Scammers will send you an email or a text message, often impersonating your coworkers or supervisor or other university official, asking you to purchase gift cards for a special event. They will usually ask you to be discreet. Often the sender will claim to be in a meeting and unable to take calls, preventing you from calling to confirm the request.
The initial email may start out innocuously, asking if you are available, stating that they need a favor, or asking for your phone number so you can receive text messages. Once you respond, the scammer will ask you to purchase gift cards, specifying the quantity and denomination. The message will ask you to scratch off the cards to reveal the codes, take pictures of those codes, and then reply back with those pictures.
If you reply with the cards’ codes, your money is now in the hands of the scammer. Gift cards are treated as cash, and in many cases, cannot be refunded.
---Start of Email---
From: <xxxxx+xxxxxx_xx_xxxxxxxxxxxx.xxx.xx @gaggle.email>
Date: Wed, Aug 28, 2024 at 5:43 PM
Subject: California State University Intern Application
Your paperwork is being processed at the moment and will be available soon.
Kindly provide the following information for further processing:
- Name of your financial institution.
- Your name just as it appears on your financial institution.
- Phone Number
- School Email Address
-Alternative Email Address
-Mailing Address
If your Direct Deposit Information is not on the school payroll system, please provide a valid account and routing number where your weekly payments can be made.
Thanks!
---End of Email---
How we know it's phishing?
- The email does not contain an official CSUN email signature.
- This email asks for personal and financial information. Legitimate institutions rarely, if ever, request such sensitive information via email.
- The message uses vague language like "your paperwork is being processed" without specifying what paperwork or providing any details about the internship. Phishing emails often avoid specifics to cast a wide net.
- The content and formatting of the email lack the professionalism expected from a legitimate university or organization.
---Start of Email---
From: <xxxxx+xxxxxx_xx_xxxxxxxxxxxx.xxx.xx @gaggle.email>
Date: Thu, Jul 4, 2024 at 10:46 AM
Subject: Courses are at risk of cancellation
You are receiving this message because you have registered and enrolled for FALL 2024 classes, however, your registration is on Hold. Your classes are scheduled to be dropped on JUlY 10th, at 5pm.
CLICK HERE TO VIEW YOUR DROPPED COURSES NOW AND APPEAL
---End of Email---
How we know it's phishing?
- The email does not contain an official CSUN email signature.
- This email expresses urgency and pressure to the recipient to take action quickly by stating their classes are scheduled to be dropped on July 10th. Phishing attempts often use this tactic to prevent the recipient from taking time to verify the legitimacy of the request.
- The instruction to "CLICK HERE TO VIEW YOUR DROPPED COURSES NOW AND APPEAL" is a common tactic in phishing scams. The link likely leads to a malicious website designed to steal your login credentials or personal information.
- The use of all caps in "JUlY 10th" and the unprofessional wording may indicate that the email was quickly put together or not written by someone fluent in English. Legitimate organizations are usually well-formatted and proofread.
Date: Sat, Jun 29, 2024 at 10:33 PM
Subject: The internship application for California State University Northridge
- The sender's email address, < >, is not a legitimate California State University Northridge (CSUN) domain. Official CSUN communications should come from a university domain, such as @csun.edu.
- The email asks recipients to submit personal information (name, email, year of study, department) via email. Legitimate internship applications are usually handled through official channels or secure online portals, not through an informal email request.
- The email mixes information about the Bill & Melinda Gates Foundation with CSUN in a way that feels unprofessional and unclear. Additionally, the message uses the name of a well-known professor but provides an @outlook.com email address, which is also not associated with the CSUN.
- The email combines several elements that don't fit together, such as referring to both the university and the Bill & Melinda Gates Foundation but lacking any official branding or signature. This inconsistency is a red flag.
---Start of Email---
From: <
>
Sent: Sunday, Apr. 2024 at 2:52:52 PM
Subject: Undercover Store Shopper
Dear Students/Staff CSUN
An evaluator is someone whose job is to judge the quality, importance, amount, or value of something. We URGENTLY need to hire the service of 10 students and staff randomly to evaluate a few local stores.
Position: Discreet Shopper & Errand Carried out.
Type: Part-Time Job
Work Flexibility: 2days a week/ 2-3hrs to complete a task
Weekends: (Sunday OFF)
Working Hour: 4-6 hours a week
Weekly Payment: $550
Get paid for doing something you enjoy. Become a digital store shopper to make extra cash on the side. Well suited job for students/staff. Be an independent contractor and work on your own schedule. Bridge gaps in your finances and help the world be a better place by giving valuable data feedback to some of the biggest brands in the States. Send { I'm Interested } to {example1@gmail.com } using your personal email address such as gmail,hotmail,icloud,yahoo and not your school email so that you can effectively receive responses from us.
California State University Northridge Students Job Placement
Discreet Shopper Opportunity
$21-$23 per hr + Benefit
Student Employment Appreciation
---End of Email---
How we know it's phishing?
- Expresses urgency to an email that users did not expect.
- CSUN has no jobs positions that consist of a "Undercover Store Shopper". The description of the position as also suspiciously vague.
- The email claims to randomly select students and staff for the job. Legitimate job offers typically require applicants to go through a proper application and selection process.
- The email promises a high weekly payment ($550) for what seems like minimal work (4-6 hours a week). This is a tactic to lure people in with the promise of easy money.
- Email asks recipients to reply using their personal email addresses (e.g., gmail, hotmail, icloud, yahoo) instead of their school email. Legitimate organizations usually communicate through official channels.
---Start of Message---
---End of Message---
How we know it's phishing?
- Help Center does not sent text messages to students.
- Help Center will never ask for a passcode.
- This message contains many errors such as spacing between words.
---Start of Email---
From: <xxxxx+xxxxxx_xx_xxxxxxxxxxxx.xxx.xx @gaggle.email>
Sent: Wednesday, March, 2024 5:01:30 AM
Subject: IMPORTANT CSUN MEMO FROM HR: ASSESSMENT REPORTS FOR FACULTY AND STAFF 2024
Hope this email finds you well.
I am pleased to inform you that the HR Department has recently finalized the Assessment Report for all staff members. It is imperative that you treat this matter with urgency.
Attached below, you will find the relevant file that contains your assessment report. Please open it to access the information.
CLICK HERE TO VIEW REPORTS
Thank you for your prompt attention to this matter.
--
Mars Cook
Undergraduate Student, Creative Writing
Peer Writing Specialist - Learning Resource Center
California State University, Northridge
---End of Email---
How we know it's phishing?
- Expresses urgency to an email that users did not expect.
- Sent at a time outside of common office hours; sent at 5:01AM
- Emails will not ask to "click here" or "click to unsubscribe".
---Start of Email---
From: <xxxxx+xxxxxx_xx_xxxxxxxxxxxx.xxx.xx @gaggle.email>
Sent: Monday, November 6, 2023 5:23:30 PM
Subject: Email confirmation
.
Click here to manage your membership or unsubscribe.
---End of Email---
*Note: The original QR code has been replaced for reference purposes only.
How we know it's phishing?
- The email does not include text, it is in an image.
- This email contains grammatical errors.
- The email asks to scan an unofficial QR code.
- Emails that do not end with @csun.edu or @my.csun.edu should be considered suspicious.
- Emails will not ask to "click here" or "click to unsubscribe".