Jump to main content

What is a Phishing Scam?

Phishing refers to the illegal attempt to obtain other people’s passwords or other login credentials. Phishing scams usually occur via e-mail. Very often, the e-mail addresses used to send phishing attempts are faked. Faking e-mails and e-mail addresses is as easy as writing someone else’s name on a postcard, so all aspects of suspicious e-mails should be examined carefully.

In most cases, phishing attempts will alert the recipient that some kind of immediate action has to be taken — often this action is some form of alleged “validation” on a faked website. Once the recipients use their login credentials for this “validation,” their input is harvested by the scamming party and may be abused in the future.
Furthermore, phishing schemes usually threaten the addressee with adverse consequences in case they do not comply with such “validation requests.” This is designed to put the target under pressure so that they will be more likely to comply with the faked request.

As such, phishing scams are an example of an attempt at social engineering: a psychological manipulation that aims to make its victims take actions which they would refrain from in situations of lower mental pressure. Such actions often involve some form of disclosure of sensitive data or information, such as passwords, credentials, or company secrets, but they may also be aimed at e.g. gaining physical access to non-public spaces.
However, this exploitation of human behaviour under (social) pressure is only the first step: account data and other information obtained through social engineering may be used as the basis for cyber attacks or other attacks on systems, services, or devices.
Thus, phishing and other social engineering techniques usually have two target levels. On the first one, the target is an individual person, and the second one is the infrastructure this person has legal access to.

This is why every single individual who uses an IT service or system bears a responsibility for the security of our IT infrastructure and should exercise caution when dealing with suspicious content or e-mails.

Phishing Scams: Questions and Answers

What does a phishing e-mail look like?

Whereas phishing attempts were quite easy to identify through their deficient grammar and orthography not too long ago, the number of linguistic giveaways in phishing e-mails has drastically declined in recent years. This means that all of us have to

1. be aware of the possibility of phishing attempts.
2. be cautious when dealing with suspicious e-mails.
3. be educated on what common techniques, phrases, and pretenses are used in phishing e-mails.

We have compiled a list of recent e-mails that have been found to be phishing attempts here. As the majority of phishing e-mails that members of our University receive are in German, this list — as of now — only contains German-language examples.
Our colleagues at UC Berkeley publish all the phishing attempts that occur at their institution. Skimming through them can give you a better idea of what such texts may look like in English.

I have received an e-mail from my own e-mail address. Have I been hacked?

We understand that a situation like this can be unsettling at first. However, it is very unlikely that your account has been hacked. This is because someone having used your e-mail address as the sending address is not the same as someone actually having gained access to your e-mail service.
As noted before, sending an e-mail under someone else’s name is as easy as writing someone else’s name on a postcard. In IT, this is called sender name/sender address spoofing.
The most likely scenario here is that a scammer simply used the letters that make up your e-mail address as a mask for the one the e-mail was actually sent from.

If you are unsure whether it is likely that you have been hacked or not, you can always reach out to the ITCC help desk to ask for advice or an examination of the e-mail you received. For this, our colleagues there will most likely request that you send them the header of the e-mail in question. In Webmail, you can read and copy the header by opening the e-mail in your inbox, then click on “Other Options” and “View Source”.

How should I react to a phishing e-mail?

The best practice for phishing e-mails usually is deleting them immediately and not reacting to them in any way. Please also refrain from forwarding the e-mail to anyone. If you would like to warn others about the e-mail, it is best to do so in a separate message.

I am not sure if the e-mail I received is a phishing attempt. Where can I ask for advice?

If you are not sure if a message that you have received is a phishing e-mail, do not hesitate to reach out to the ITCC help desk.

How to detect fraudulent e-mails

Other Types of Attacks via E-Mail

Spear Phishing

Whereas the average phishing attempt is distributed to several hundred or thousand persons at the same time, there is another form of phishing that is highly targeted and, as such, more dangerous: Spear Phishing.
Spear phishing attempts usually are scam e-mails that are sent to as few as one individual person and contain highly specialized content that is tailored to the target’s interests, correspondences or work environment, which may look authentic even under closer inspection. As such, spear phishing is a particularly insidious type of scam. We have compiled a separate information page on Spear Phishing here.

Blackmailing via e-mail

"Help, someone writes that I have been hacked and he has got compromising records about me! I should pay a ransom, otherwise he will send these records to my relatives and acquaintances!" However, most of the time this type of threatening email is sent without providing any evidence. Learn more about typical blackmail attempts on our page dedicated to these scams.

Giftcard Scamming

What is giftcard spam? Scammers send messages to employees in the name of their superior (professor, supervisor, head of management) from an external e-mail address (e.g., Gmail, Yahoo). They pretend that the matter is urgent and that they can only be contacted via this external e-mail address. The victims are put under pressure and are persuaded to buy gift cards and hand over the gift card codes.

Find out more about Giftcard Scams.