Phishing bowl: Staying vigilant against phishing

Email icon caught in a fishing hook inside a fish bowl

The Phishing Bowl is a list of recent email messages or trends the Information Security team is seeing on campus. Refer to these resources to spot illegitimate emails and phishing attempts.

Recent Phishing Bowl entries

Your vigilance against phishing is crucial.

  1. Red Warning Banner: A red warning banner at the top of an email is a sign that the email was not generated within the University of Missouri System. If this banner is present, you should always proceed with caution, utilizing the following tips.
  2. Verify the Sender: Be cautious of emails from unknown or unexpected senders, even if the “From” address appears to be from a trusted source.
  3. Never click links in unsolicited or suspicious emails:  Before clicking, hover your mouse over the link (or use a “long press” on a mobile device) to reveal the actual URL in the bottom corner of your screen.
  4. Check the URL: Ensure the displayed URL matches the website it’s supposed to link to. If you see a link shortener (like bit.ly) or an unfamiliar domain, do not click it.
  5. Navigate Manually: If you are unsure about a link’s legitimacy, open a new browser tab and manually type the website’s address or go to it from a trusted bookmark.
  6. Be Skeptical of Requests for Information: If an email asks you to log in or provide personal information after clicking a link, it could be a phishing attempt. Go to the website directly instead.

Report any suspicious email.

  • Use Outlook’s “Report Message” button.
  • Even if you don’t engage with a phishing email, report it to alert our teams.
  • Prompt reporting of phishing emails allows the security team to remove malicious emails from all mailboxes thus reducing the threat for other users.

Multifactor Authentication (MFA) reminders.

  • The university will never text you directly and ask for your multifactor authentication code.
  • Never enter your authentication code unless you have initiated the login process through a trusted service first.
  • For enhanced security, update your MFA method to use the Microsoft Authenticator app instead of a text message using these instructions.