Category: Phishing & Social Engineering
Stay Alert: How to Recognize and Report Phishing
August 25, 2026 Written by Frank Handschuh
As the new academic year begins, the University of Delaware is seeing an increase in phishing attempts targeting members of the UD community, particularly students. Phishing messages are designed to trick you into clicking a link, opening an attachment, sharing your credentials or sensitive information, or taking an action that could put your account or information at risk.
Phishing messages can look convincing. They may appear to come from a friend, colleague, University department, vendor, or other trusted organization. Taking a moment to pause and verify a message can help protect your account and the University community.
How to Spot a Phishing Attempt
Before clicking a link or responding to an unexpected message, keep these tips in mind:
Pause and think. Be cautious of messages that create a sense of urgency or pressure you to act quickly. Scammers often use urgent language to make you act before you have time to think.
Check the sender. Look carefully at the sender's full email address, not just the display name. If a message from a colleague, friend, or vendor seems suspicious, verify it using a separate, trusted communication method, such as a phone call or Microsoft Teams message.
Be cautious with links and attachments. Don't click unexpected links or open attachments until you've verified they are legitimate. A link that appears legitimate can actually lead to a malicious website. On a computer, hover over a link to preview its destination before clicking. On a mobile device, tap and hold the link to view the destination. When possible, the safest option is to open a new browser window and manually enter the website address yourself.
Never provide sensitive information by email. Never provide passwords, financial information, or other sensitive personal information in response to an email. If a request appears legitimate but asks you to take an unusual or urgent action, verify it independently using a trusted contact method before taking any action.
Think You Received a Phish?
Don't click, respond, or provide information. Report suspicious messages using the Phish Alert Button in your email client. The Phish Alert Button sends the message to UDIT for review.
You can also forward suspected phishing emails to reportaphish@udel.edu.
Prompt reporting helps UDIT take steps to protect your account and the University community.
Think You May Have Fallen for a Phish?
If you clicked a suspicious link, provided your credentials, or otherwise believe you may have fallen victim to a phishing attack, contact the IT Support Center immediately at (302) 831-6000 or AskIT@udel.edu. Prompt reporting can help limit potential impact and protect your account.
Learn More About Phishing
Want to learn more about identifying phishing attempts? Review these resources:
60 Seconds on Phishing — A quick video with tips for identifying phishing.
Phishing in Your Inbox — Learn how to recognize common signs of phishing.
10 Common Traits of Phishing Emails — Spot common characteristics of phishing messages.
When in doubt, stop, verify, and report.