Keep Clearing Safe: tips to identify and deal with a phishing message

Information Security is everyone’s responsibility. Here we share how to identify and report phishing messages, to keep you, your data and our systems safe.

Phishing scams often target people at particularly busy times, such as during Clearing or at the start of a new term.

Cyber criminals are hoping that your guard is down, and they use messages designed to trigger emotions like curiosity, urgency, fear or excitement. Their goal is often to gain access to your personal information, university accounts, or data you may have access to through your role.

Follow these simple tips to help stay safe:

1. Stop and think

Phishing messages rely on people acting quickly without checking first.

If something doesn't feel right, pause before clicking a link, replying to a message or sharing information. Take time to check that the request is genuine.

2. Check twice, click once

Report phishing and junk emails with the Microsoft Report Message button in Outlook. This tool will help us quickly identify phishing threats and take action to keep your data and our systems safe. You no longer need to manually forward the email to the IT Service Desk.

Cyber criminals often impersonate university staff using publicly available information. Always check the sender's email address, not just the display name. Messages from outside Greenwich are always flagged as External. Pause, verify and block any suspicious contact.

3. Be suspicious

Be wary of messages claiming there's a problem with your device, asking you to install software, or requesting your one-time passcode.

The IT Service Desk and your internet provider will not contact you out of the blue to fix a problem. They will never ask for your multi-factor authentication (MFA) codes or passwords.

Any new university IT systems or processes will be communicated through official channels, such as Staff News or emails from the IT Service Desk.

4. Be security conscious

Even when you're not studying or working. Hoaxers don't care how they get through to you. For example, WhatsApp have released guidance on hoax messages. Take extra care with QR codes in emails, as they can direct you to malicious websites.

5. Think about what you send too

Remember to always check your messages before you press send – are you sending it to the correct recipients?

6. Log out of shared devices

If you're studying from home and sharing devices with family, remember to log out of university systems, don't leave them logged in. This helps protect your account and university data from unauthorised access.

Learn how to spot a phishing scam

Using real-life examples, it explains how to assess messages critically, identify warning signs and protect yourself from common phishing tactics.

You've identified a malicious message, what next?

If you receive a suspicious email, do not click on any of the links or attachments. Use the Microsoft Report Message add-in for Outlook to notify IT Service Desk. Find out more about reporting suspicious messages here.

If you suspect you have clicked on a malicious link, or have any questions please contact the Information Security team by raising a ticket with the IT Service Desk.

Current staff

TLDRoffon