InfoSec

Phishing Bowl: Email could be the start of a bigger attack

Email icon caught in a fishing hook inside a fish bowl

Aug. 31, 2026

Most of us have seen them: an email asking us to reset a password, review a document, confirm an account, pay an invoice or respond to an urgent request.

Sometimes they’re obviously fake. Other times, they look surprisingly convincing.

It’s easy to delete the suspicious ones and move on. But phishing isn’t just about getting someone to click a bad link. For a cybercriminal, a convincing email can be the first step toward gaining access to an account, stealing information or disrupting an organization’s operations.

And when that happens, the consequences can extend well beyond the person who received the original email. 

A phishing message can become a much bigger problem

Attackers don’t necessarily need to break through a university’s security systems if they can convince someone to let them in.

A stolen username and password can provide access to email, files and other university resources. From there, an attacker may be able to find additional information, impersonate the account holder, send more convincing phishing messages to coworkers, or gain access to other systems.

That’s one reason phishing remains such an important cybersecurity issue in higher education. Universities have a lot of information worth protecting and many people who interact with it every day.

The consequences of a successful attack can be significant.

In May 2026, the University of Missouri System was among thousands of educational institutions affected by a cyberattack involving Canvas. The incident affected the UM System’s Canvas environment as well as many other schools using the platform. Read this KBIA report about the Canvas incident.

While that incident involved a technology provider rather than a traditional phishing attack against an individual UM System employee or group of employees, it illustrates what can happen when a widely used system is compromised. Students and employees can lose access to tools they depend on, and organizations can spend significant time investigating, recovering, and communicating about an incident.

What could someone do with your account?

Consider what you have access to through your university account.

You may have access to email conversations, documents, financial information, student information, research data, employee information or systems that other people depend on.

An attacker who gets your credentials may not be interested in reading your email just for the sake of reading it. Your account can be useful because it gives them a trusted identity inside the organization.

A compromised account could be used to:

  • Send phishing messages to coworkers who are more likely to trust a familiar name
  • Access sensitive university information
  • Redirect payments or request fraudulent purchases
  • Steal personal or financial information
  • Gain access to additional accounts or systems
  • Disrupt university operations

And sometimes the damage starts with something as simple as a convincing email.

Phishing doesn’t always look like phishing

Today’s phishing messages aren’t necessarily filled with spelling mistakes and strange graphics.

Attackers can make messages appear to come from a coworker, supervisor, vendor or a familiar service. They may use information they’ve gathered about an organization to make the request more believable or use a compromised account to phish others.

The message might say:

“Can you take care of this before the end of the day?”

Or:

“Your account requires verification.”

Or:

“Your student loan information has been updated. Click here to view.”

The goal is usually the same: get you to do something before you stop to think about whether the request makes sense.

That’s why one of the most useful habits you can develop is simply slowing down.

Three things to remember: Pause. Verify. Report.

1. Pause

If an unexpected message creates a sense of urgency, take a moment.

Don’t click immediately. Don’t enter your password. Don’t approve an MFA request just because it appeared on your phone.

Ask yourself:

Was I expecting this? Does the request make sense? Would I normally receive this kind of message from this person or organization?

2. Verify

If something seems unusual, verify the request using a method you trust.

  • If an email appears to come from your supervisor asking you to purchase something, contact them through a known phone number or separate message.
  • If you receive an unexpected password-reset message, go directly to the service rather than clicking the link in the email.
  • If someone asks for sensitive information, confirm that the request is legitimate before sending it.

3. Report

You don’t have to be certain that something is phishing before you report it.

In fact, reporting a suspicious message may be one of the most useful things you can do.

Security teams can investigate the message, identify whether other people received it and take action to prevent additional accounts from being compromised.

And if you already clicked something or entered your credentials, report it anyway.

Don’t be embarrassed and don’t wait to see what happens. The sooner a potential compromise is reported, the more options there may be to contain it.

What if I already clicked?

Phishing messages are designed to look legitimate, and even people who know what to look for can occasionally be fooled.

If you click a suspicious link, open an unexpected attachment, provide your password or approve an MFA request you didn’t initiate, report it through the appropriate UM System or campus process as soon as possible.

Quick reporting gives security teams an opportunity to investigate and respond before a small problem becomes a much larger one.

The goal isn’t to recognize every phishing email

No one is expected to identify every attack perfectly. The goal is to develop a habit of stopping when something feels unusual.

The next phishing message you receive may look completely different from the examples you’ve seen before. What matters is knowing what to do when you encounter it.