Digital Literacy and Phishing: How to Avoid Scam Emails

Citrus College students have encountered phishing scams in their campus email inboxes as they continue to work remotely.

Phishing is the imitation of a reputable company or organization in order to extract valuable information such as email addresses, phone numbers and passwords, writes phishing.org. These emails or links are entirely fake and exist for the sole purpose of luring people into giving up information. 

Phishing scams appear to be legitimate requests for personal information, usually coming from the email addresses of staff or other students. 

Chief Information Services Officer Bob Hughes confirmed in an email interview that the school is experiencing an increase in scam emails from inside and outside the Citrus College network. 

“We have recently increased our efforts to combat scam and phishing e-mails by limiting the functionality of new accounts, limiting the number of e-mails that an individual student account can send, deleting spam e-mail from accounts, and proactively disabling accounts that send spam,” Hughes said.

These fraudulent email accounts come from fake student accounts and accounts from former students that are no longer in use, Hughes said. 

Courtesy of Caleb Anderson

“It was obviously a phish scam because the email address that it was from was a citrus student email,” Anderson said in a text interview. “An email asking for such information should be from some sort of administration IT.” 

Anderson was not the only student to receive this particular email.

“It doesn’t make sense for the school to send out this email,” Citrus student Anthony Fonseca said in a phone interview. “I don’t think it is necessary for people to have to verify our emails in this way. I would never give out my password unless I was sure it was the college.”

Small inconsistencies, such as the fact that this email came from a student account, can help one identify the legitimacy of these emails. 

Hughes suggests students and staff work together to combat phishing by not responding, deleting and flagging spam emails as “junk” in their Office 365 account.

Share