Not sure if a message is trustworthy? Don't click on it, don't respond, and report it. Better to report one too many than one too few.
What is phishing?
Phishing is a form of digital fraud in which criminals impersonate a trustworthy organization, colleague, supplier, or well-known service.
The goal may be to:
- steal usernames and passwords;
- collect personal information;
- steal financial information;
- gain access to systems and accounts;
- install malicious software.
Phishing usually occurs via email, but it can also happen via text message (smishing), WhatsApp, social media, and phone calls.
Why are you an attractive target?
Many people think, “Why would criminals be interested in me?” Yet everyone at VU is a potential target.
Cybercriminals often send out thousands of messages at once. They hope that someone will respond, click on a link, or enter their information. It doesn’t matter whether you’re a student, researcher, faculty member, or staff member.
Your account could grant access to:
- VU systems and applications;
- research information;
- contact information for colleagues, students, and external partners;
- personal data;
- Teams, SharePoint, and OneDrive environments.
Student accounts are also valuable. Furthermore, a compromised account can be misused to send new phishing messages that appear to come from a trusted VU sender.
How can you spot phishing?
Phishing messages are becoming increasingly convincing. Therefore, always carefully verify whether a message is trustworthy.
The sender is suspicious
- The email address does not match the sender’s name.
- The domain contains spelling errors or strange characters.
- The message appears to come from a well-known organization but is sent from an unknown address.
Pressure is being applied
Criminals often try to get you to act quickly.
Examples:
- "Your account will be blocked today."
- "Action required within 24 hours."
- "Suspicious activity has been detected."
- "Your mailbox is almost full."
You are asked to provide confidential information
Be extra vigilant when asked for:
- passwords;
- MFA or verification codes;
- personal information;
- bank or payment information.
Links may not be trustworthy
Always check where a link actually leads before clicking on it. Hover your mouse over the link to view the web address.
The message contains errors
Note:
- spelling errors;
- unusual sentence structure;
- strange formatting;
- poor translations.
The request comes unexpectedly
If you unexpectedly receive a request from a colleague, supervisor, supplier, or other known party, verify through another channel whether the request is genuine.
What does the VU never do?
The VU will never ask you via email to:
- share your password;
- provide an MFA code;
- confirm your password;
- provide personal or financial information without a clear reason;
- transfer money to an unknown account.
If you do receive such a request, be extra vigilant and, if in doubt, contact the IT Service Desk.
What should you do if you’re unsure?
Are you unsure whether a message is legitimate?
Do not click on links
Do not open attachments
Do not reply to the message
Do not share any information
Report the message
When in doubt, remember: it’s better to report one message too many than one too few.
How do you report phishing?
Have you received a suspicious message? Report it immediately.
Preferably use the “Report Phishing” button in Outlook
Do you use Outlook for Windows, Mac, or Outlook on the web? Report suspicious messages using the built-in reporting feature.
- Open or select the suspicious message.
- Select Report, Report Message, or Report Phishing.
- Select “Phishing.”
- Follow the on-screen instructions.
The message will be forwarded for analysis and may be automatically removed from your inbox.
Can’t use the reporting feature?
Can’t find the option, or are you using a different email application? If so, forward the message to servicedesk.it@vu.nl.
If possible, please include the following:
- that you suspect it is a phishing attempt;
- whether you clicked on a link;
- whether you opened an attachment;
- whether you entered any information;
- any other actions you may have taken.
Have you already clicked on a link or entered any information?
Don’t panic, but take immediate action.
Contact the IT Service Desk as soon as possible if you:
- have clicked on a suspicious link;
- have opened an attachment;
- have entered your username or password;
- have shared an MFA code;
- have provided personal information;
- shared other confidential information.
The sooner an incident is reported, the greater the chance that any damage can be minimized.
IT Service Desk
Email: servicedesk.it@vu.nl
Phone: 020 59 80000
Available: weekdays from 7:30 a.m. to 5:00 p.m.
You can also visit the IT Service Desk counters:
- VU Main Building: 0A-11
- W&N Building: M0-20
The service desks are open on weekdays from 9:00 a.m. to 5:00 p.m.
Common phishing techniques
Cybercriminals frequently impersonate:
- Microsoft;
- Vrije Universiteit Amsterdam;
- banks;
- parcel delivery services;
- government agencies;
- suppliers;
- colleagues or supervisors.
Existing email conversations can also be misused to make a message appear credible.
Therefore, stay alert, even when a message appears to come from someone you know.
Together, we keep the VU safe
Information security is a shared responsibility. By recognizing and reporting suspicious messages, you help ensure a safe digital learning, research, and work environment for everyone at the VU.
See something suspicious? Report it immediately. Together, we keep the VU safe.