This site requires JavaScript to be enabled
An updated version of this article is available. You can only edit the latest version of the article
3716 views

11.0 - Updated on 2025-03-17 by Denise Moser

10.0 - Updated on 2024-03-13 by Denise Moser

9.0 - Updated on 2024-03-05 by Denise Moser

8.0 - Updated on 2023-08-17 by Cassie McCan

7.0 - Updated on 2023-03-06 by Denise Moser

6.0 - Updated on 2021-03-04 by Denise Moser

5.0 - Updated on 2020-03-13 by Matthew McGuire

4.0 - Updated on 2020-01-30 by Denise Moser

Phishing is the use of email and fraudulent websites to trick people into disclosing personal financial or identity information, such as credit card or Social Security numbers, user names (e.g., NetIDs), passwords and addresses. Although most "phishes" come as email, phishing scams can also come in the form of text messages and phone calls. It's called "phishing" because the criminals are broadcasting phony emails to large numbers of addresses, and they're hoping the recipients will "take the bait." The emails will either try to entice you with promises of great deals or scare you into providing the information.

Phony emails are sent from addresses across the Internet and appear to be from reputable organizations, but are not. The emails are actually from criminals who are attempting to lure you to provide your personal information. Often both the emails and the web pages they direct you to look just like you would expect to see from that organization since the logos and formats have been copied. The message uses social engineering tactics that might indicate there is a problem with your account and urges you to respond immediately by clicking a web link to "verify" or "update" your account information.

It's important to note, that the company that is being spoofed has nothing to do with the scam. Their name is just being used to trick you into "taking the bait."

What are some examples of phishing?

If you receive an email soliciting confidential information such as your password, Social Security Number, credit card number, or other sensitive information, with instructions to send it via email, this is likely a scam. Email messages travel over the Internet in an insecure manner, and you should never send sensitive information in an email. Notre Dame will NEVER request you provide this information via e-mail. 

How to Recognize Scams

Scam tactics are increasingly sophisticated and change rapidly. Even if a request looks genuine, be skeptical and look for one or more of these warning flags:

You can also review our short Scam School Videos for further information.

How to Report Scams

To report a scam to Google and the OIT to aid us in blocking further messages from the sender, follow these instructions.