{"id":2952,"date":"2018-09-17T03:57:57","date_gmt":"2018-09-17T03:57:57","guid":{"rendered":"https:\/\/in.nau.edu\/its\/emailphishing\/"},"modified":"2025-10-07T18:56:53","modified_gmt":"2025-10-07T18:56:53","slug":"emailphishing","status":"publish","type":"page","link":"https:\/\/in.nau.edu\/its\/emailphishing\/","title":{"rendered":"Email Phishing"},"content":{"rendered":"<h6 style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-20525 \" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-600x478.png\" alt=\"An icon with two chat bubbles, one with an exclaimation mark inside.\" width=\"154\" height=\"123\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-600x478.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-300x239.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-1024x816.png 1024w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-768x612.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-1536x1224.png 1536w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2025\/02\/bubble.exclaim.nofill-2048x1632.png 2048w\" sizes=\"auto, (max-width: 154px) 100vw, 154px\" \/><\/h6>\n<h3 style=\"text-align: center\"><span id=\"ctl00_ctl00__main__main_lblHead\">Email Phishing<\/span><\/h3>\n<p style=\"text-align: center\"><a href=\"mailto:phishing@nau.edu\">phishing@nau.edu<\/a> \u2022\u00a0<a href=\"tel:9285233335\">(928) 523-3335<\/a><\/p>\n<div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-60px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h4>Reporting a Phish<\/h4>\n<p>If you caught a phish, or <em>think<\/em> you&#8217;ve caught a phish, you can report it by the following methods.<\/p>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h5>Built-in reporting options in your email client<\/h5>\n<ul>\n<li>For anyone with an NAU email through Outlook or Gmail, the built-in Reporting option is preferred. It is available for on most devices and ways of accessing your email, though it is currently not available for Gmail Mobile.<\/li>\n<\/ul>\n<h5>Forward an email to phishing@nau.edu<\/h5>\n<ul>\n<li>If the built-in reporting option is not available, forwarding the email to phishing@nau.edu is always an option. You don&#8217;t need to provide screen shots, attachments, or headers like we used to ask you for. Just hit forward and drop phishing@nau.edu in the &#8220;To:&#8221; box. We&#8217;ll take it from there.<\/li>\n<\/ul>\n<p>Want further details on how to report for your client? Check out our Knowledge Base Article on <a href=\"https:\/\/servicenow.nau.edu\/kb_view.do?sys_kb_id=fd4b6879c3310ad0f7eaf4fdd401318b\" target=\"_blank\" rel=\"noopener\">reporting a phish<\/a>.<br \/>\n<\/div><\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<div class=\"eplus-bg-color-row bg-color-extra-light-gray\"><div class=\"eplus-bg-color-row-content\">\n<h4>General Phishing<\/h4>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What is phishing?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What is phishing? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Phishing is the process of a malicious entity attempting to acquire sensitive information such as usernames, passwords, and financial details by masquerading as a trustworthy source in an email or other electronic communication in order to steal your data, access University systems, or install malware.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"How do I know I\u2019ve received a phish?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>How do I know I\u2019ve received a phish? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Many phishing attempts will request that you take action by clicking a link or performing a strange action, such as sending a gift card or personal financial details. However, in today&rsquo;s day and age, phishing has gotten more advanced; they are no longer easy to spot and comical in demands&hellip;your Nigerian Prince is not going to send you money.&nbsp; Modern phishing attempts are well executed and getting harder and harder to spot.<\/p>\n\n<p>This is to say, you may not <em>know.<\/em> If you are ever unsure, you can have us check for <em>unusual behavior on the email<\/em> by reporting.<\/p>\n<div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n<\/div><\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"I think I clicked on something I shouldn\u2019t have, now what?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>I think I clicked on something I shouldn\u2019t have, now what? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>First, don&rsquo;t panic. Many times, quick reporting can help mitigate the negative impacts of the accidental click. Then:<\/p>\n<ul>\n<li>Close the browser<\/li>\n<li>Report it.<\/li>\n<li><a href=\"https:\/\/id.nau.edu\/passwordchange\/\">Change your password<\/a> if you shared it.<\/li>\n<li>If you are receiving an unsolicited Two-Step Verification push notification, <strong><a href=\"tel:9285233335\">contact the ITS Service Desk<\/a><\/strong> for assistance in recovering your account.<\/li>\n<li>If you notice any unusual downloads or unexpected behaviors on an NAU supported devices, <strong><a href=\"tel:9285233335\">contact the ITS Service Desk<\/a><\/strong> to have it evaluated.<\/li>\n<\/ul>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"I accidentally reported an email what do I do?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>I accidentally reported an email what do I do? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>If you have accidentally reported an email just send a message <a href=\"mailto:phishing@nau.edu\">phishing@nau.edu <\/a>and let us know which one it was. We can return it to you.<\/p>\n\n<p>A common cause of accidental reports is the fact that the &ldquo;Archive&rdquo; button and the &ldquo;Report&rdquo; button are side by side. If you frequently use the &ldquo;Archive&rdquo; button you may prefer to move it to another location in your ribbon. You can follow<a href=\"https:\/\/support.microsoft.com\/en-us\/office\/customize-the-ribbon-in-office-00f24ca7-6021-48d3-9514-a31a460ecb31\" target=\"_blank\" rel=\"noopener\"> the instructions provided by Microsoft.<\/a><\/p>\n<div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n<\/div><\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Can I move the report button?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Can I move the report button? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Yes, follow<a href=\"https:\/\/support.microsoft.com\/en-us\/office\/customize-the-ribbon-in-office-00f24ca7-6021-48d3-9514-a31a460ecb31\" target=\"_blank\" rel=\"noopener\"> the instructions provided by Microsoft.<\/a><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What could happen if you fall for a phish?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What could happen if you fall for a phish? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>If you click on a phishing link, or open a malicious attachment, several things can happen:<\/p>\n<p>Your personal information may be stolen.&nbsp; Phishing attacks often involve tricking people into entering their personal information, such as login credentials, DUO authentication codes, credit card numbers, etc. into a fake website.&nbsp; If you happen to provide this information to the bad actors, it can be used to steal your identity, commit fraud, or other malicious purposes.<\/p>\n<ul>\n<li>Malware can be installed on to your device.&nbsp; Phishing emails may contain links or attachments that, when clicked, can download malware onto your device which can take control of your device, spy on you, steal your work or personal information, or use your device to continue spreading the attack.<\/li>\n<li>Your accounts can be compromised.&nbsp; If you enter your login credentials or DUO authentication codes on to a fake website, the bad actors can use that information to log into your actual accounts and take them over, which can lead to theft of your work or personal information and even cause financial loss.<\/li>\n<li>Your device can be locked or encrypted.&nbsp; Some phishing attacks involve ransomware, which can lock or encrypt your data or data you have access to and demand a payment to unlock the data or prevent publicly disclosing the data.<\/li>\n<\/ul>\n<p>Clicking on a phishing link or opening a malicious attachment can have serious consequences for you, your department, and NAU.&nbsp; It is important to always be cautious and verify the authenticity of emails and links before clicking on anything.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Common phishing signs_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Common phishing signs <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<ul>\n<li>The message is poorly written; it may contain strange grammar and spelling.<\/li>\n<li>Requests that you provide personal information such as your NAU password, credit cards, bank accounts, phone numbers, addresses, etc.<\/li>\n<li>The email contains a strange attachment you weren&rsquo;t expecting.<\/li>\n<li>Attempts to scare the recipient by creating a sense of urgency by threatening to close accounts, overdraw funds, etc.<\/li>\n<li>Offers for jobs, awards, or other incentives that are too good to be true.<\/li>\n<li>The &lsquo;from&rsquo; address doesn&rsquo;t seem correct, or does not match the domain of where the message was sent.<\/li>\n<li>Requests for money or donations.<\/li>\n<\/ul>\n<p><em>*It&rsquo;s important to note that even if an email doesn&rsquo;t contain these indicators, it may still be a phish!<\/em><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<\/div>\n<div id=\"ctl00_ctl00__main__main_ContentBlock1\"><\/div>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h4>Real Examples of Phishing at NAU<\/h4>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Example of a fake CAS login page_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Example of a fake CAS login page <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>This login page looks authentic, but is actually identifiable as fraudulent upon closer inspection. The end of the domain address (everything before the &lsquo;slash&rsquo;, or &lsquo;\/&rsquo;) ends in &lsquo;.com&rsquo; instead of &lsquo;nau.edu&rsquo;. If a user is in a hurry or careless, they can see the &lsquo;nau.edu&rsquo; and overlook this. This is a cheap trick used by cyber-criminals, but is still very effective for an inattentive user to fall for.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13882 size-uncropped-large\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_example2-600x547.png\" alt=\"Fake NAU login page with the domain ending in .com, and not nau.edu. \" width=\"600\" height=\"547\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_example2-600x547.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_example2-300x274.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_example2-768x700.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_example2.png 1010w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n<p><em>Always check the URL of any site that you intend to enter your NAU credentials in. The best cybersecurity defense is your own perception.<\/em><\/p>\n<\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Example of a fake DUO page_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Example of a fake DUO page <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n\n<p>Using what was shown in the previous example, we can see that this DUO prompt is fraudulent based off the domain URL, which ends in &lsquo;.com&rsquo; instead of &lsquo;nau.edu&rsquo;. Again, the attackers attempt to catch users off-guard by including &lsquo;nau.edu&rsquo; after the slash.<\/p>\n<p><em>NAU Users should also be able to recognize that this isn&rsquo;t what our NAU DUO page currently looks like. This is an outdated DUO page, with only one option for authentication. NAU also does not provide a &lsquo;remember me for 90 days&rsquo; option.<br>\n<\/em><\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13901 size-uncropped-large\" src=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_exampleDuo-600x431.png\" alt=\"A fake DUO prompt, with a domain ending in .com, and the incorrect interface.\" width=\"600\" height=\"431\" srcset=\"https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_exampleDuo-600x431.png 600w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_exampleDuo-300x216.png 300w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_exampleDuo-768x552.png 768w, https:\/\/in.nau.edu\/wp-content\/uploads\/sites\/162\/2022\/12\/phishing_exampleDuo.png 1005w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>If an NAU user were to enter their user ID and password, followed by their DUO one-time password; they would be granting a cyber-criminal full access to their financial account, direct deposit, social security, tax information, addresses, and more.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-15px not-in-view\">\n<h4>Report Phishing<\/h4>\n<hr role=\"separator\" class=\"hr--transparent hr--transparent-30px not-in-view\">\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What should I do if I receive a phishing email?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What should I do if I receive a phishing email? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n\n<p>If you receive a phishing email, don&rsquo;t respond to it, click on links, or open attached files. Easily report a phish by using one of the two following options:<\/p>\n<ul>\n<li>From an Outlook client, Outlook on the web, or Gmail client select the suspected phishing email and Click Report and then Report Phishing. This option automatically reports the phishing email to our security team and remove the phishing email from your inbox.<\/li>\n<li>If you do not have the report phishing option in your client, please forward the original suspected phishing to Phishing@nau.edu. After you&rsquo;ve reported the email, please delete it from your inbox.<\/li>\n<\/ul>\n<\/div>\n<p>If you believe your NAU account was compromised, immediately <strong><a href=\"https:\/\/id.nau.edu\/passwordchange\">change your password<\/a><\/strong>, and <strong><a href=\"tel:9285233335\">contact the ITS Service Desk.<\/a><\/strong><\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"How do I report?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>How do I report? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>Your reporting options depend on what you are using:<\/p>\n<ul>\n<li>From an Outlook client, Outlook on the web, or Gmail client select the suspected phishing email and Click Report and then Report Phishing. This option automatically reports the phishing email to our security team and remove the phishing email from your inbox.<\/li>\n<li>If you do not have the report phishing option in your client, please forward the original suspected phishing to Phishing@nau.edu. After you&rsquo;ve reported the email, please delete it from your inbox.<\/li>\n<\/ul>\n<p>We are no longer requesting headers or asking University Community Members to use our retired Report a Phish application.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Is it safe to forward the phish?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Is it safe to forward the phish? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><div id=\"ctl00_ctl00__main__main_ContentBlock1\">\n\n<p>Yes, <em>if you forward it to <a href=\"mailto:phishing@nau.edu\">phishing@nau.edu<\/a>. <\/em>This mailbox is specifically setup to allow NAU&rsquo;s security team to safely examine and evaluate suspicious emails.<\/p>\n<\/div>\n<div><\/div>\n<div>No, if you forward it to your supervisor, co-workers, or other University Community Members. While it can be tempting to attempt to warn your coworkers or ask them if they think it is a phish, forwarding the potentially malicious email can cause it to spread further and faster.<\/div>\n<div><\/div>\n<div><\/div>\n<div>You should not forward or share suspected phishing emails to any email other than <a href=\"mailto:phishing@nau.edu\">phishing@nau.edu<\/a>.<\/div>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"What if I\u2019m wrong?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>What if I\u2019m wrong? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>After reviewing the reported email, we&rsquo;ll let you know if we do not evaluate the email to be an active threat and thank you for your report. It is far easier to proactively check an email for suspicious behavior, than it is to clean up accounts and devices after a University Community Member clicked on a bad link.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<!-- shortcode-accordion -->\n<div class=\"shortcode-accordion shortcode-accordion--closed\" style=\"position: relative;\" >\n        <a class=\"shortcode-accordion__trigger\" data-header=\"Why should I report?_0\" href=\"#\">\n      <div class=\"shortcode-accordion__header\">\n          <h4>Why should I report? <span class=\"screen-reader-text\">Accordion Closed<\/span><\/h4>\n          <span class=\"shortcode-accordion__header__arrow\"><\/span>\n      <\/div>\n    <\/a>\n    <div class=\"shortcode-accordion__body\">\n        <!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body>\n<p>If you were walking down the hallway and saw a potential tripping hazard or spill that you couldn&rsquo;t clean up yourself, you would call it in. Facility Services would then come out and make that spot in our University safe again.<\/p>\n<p>Reporting potential email hazards, phishing, enables our Security Operations Team to clean up that spot in our University systems.<\/p>\n<p>By reporting phishing emails you make NAU safer for all of our Community Members.<\/p>\n<\/body><\/html>\n\n    <\/div>\n<\/div>\n\n<p>If you have any other questions, comments, or feedback you can reach us by opening a <a href=\"https:\/\/servicenow.nau.edu\/sp?id=create_incident&amp;sys_id=0e9c5c270fa0c30053dbeee692050e33\">ServiceNow Ticket<\/a>.<\/p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Email Phishing phishing@nau.edu \u2022\u00a0(928) 523-3335<\/p>\n","protected":false},"author":1,"featured_media":13835,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","ring_central_script_selection":"","footnotes":""},"class_list":["post-2952","page","type-page","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/2952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/comments?post=2952"}],"version-history":[{"count":102,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/2952\/revisions"}],"predecessor-version":[{"id":22277,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/pages\/2952\/revisions\/22277"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/media\/13835"}],"wp:attachment":[{"href":"https:\/\/in.nau.edu\/its\/wp-json\/wp\/v2\/media?parent=2952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}