Learn how to recognize phishing attacks targeting NCU students, faculty, and staff — including how AI has changed the threat, the most common scams at NCU, and what to do if you receive or fall for a suspicious message.
What is phishing?
Phishing is any attempt to trick you into giving up credentials, money, or personal information by pretending to be someone you trust. It arrives by email, text message (smishing), phone call (vishing), or fake websites, often several at once.
Universities are high-value targets: open, trust-based communities with easy-to-find email addresses and a wide mix of security awareness.
How AI has changed phishing
"Look for typos and bad grammar" no longer works. Attackers use AI to write flawless, personalized messages at scale.
|
Old phishing (before AI)
|
AI-enhanced phishing (now)
|
- Obvious typos and broken grammar
- Generic "Dear User" greetings
- One-size-fits-all messages
- Easily caught by spam filters
|
- Perfect spelling, grammar, and tone
- Uses your name, role, or department
- References real people at NCU
- Mirrors the voice of NCU communications
|
A polished, well-written message is not a sign it's safe
AI writes professional messages in seconds and researches NCU's org chart and staff directories first. The name, title, and context may all check out. The sender's address or phone number is often the only thing that's wrong.
Common scams at NCU
Executive impersonation, smishing & gift card scams
Mostly targets staff
A scammer pretends to be a dean, cabinet member, or your supervisor, usually by text. It starts small ("Are you available?") and then asks for a favor: buy gift cards and send the codes, or send a file without going through the normal process.
|
Red flags in the message
|
Red flags in the request
|
- Arrives by text, not NCU email
- Opens with "Are you available?" or "Can I ask a favor?"
- Sender is "in a meeting" or "traveling" and can't talk
- Comes from Gmail or an unfamiliar number
|
- Gift cards, wire transfers, or Zelle
- Asks you to skip a normal approval
- Asks you to keep it confidential
- Promises to reimburse you
|
Example — gift card text
"Hi, this is [Dean's name]. I'm in back-to-back meetings and can't talk. I need you to pick up 4 Apple gift cards — $100 each — for a donor recognition gift. I'll reimburse you today. Please keep it between us for now."
Why it works: It names a real person, creates urgency, offers reimbursement so it feels legitimate, and asks for secrecy so you won't check.
NCU leadership never asks for gift cards, and never by text. A real supervisor will take a phone call. Call them on a number you look up yourself, not one from the message.
Spear phishing & fake login pages
Mostly targets faculty and staff
A targeted email that looks like it came from NCU Payroll, HR, or IT links to a fake Microsoft sign-in page. Whatever you type there, including your password and MFA approval, goes straight to the attacker, who then uses your account to phish others.
|
Red flags in the email
|
Red flags on the sign-in page
|
- Unexpected alert about payroll, benefits, or your password
- Sender isn't exactly @northcentral.edu (watch for northcentra1.edu)
- A deadline: "your access will be suspended"
- Hovering over the link shows a non-NCU address
|
- Address bar shows anything other than login.microsoftonline.com or northcentral.edu
- You got there by clicking a link in an email
- It asks for your password and MFA code on the same page
|
Example — payroll email
"Action required: NCU Payroll has updated its direct deposit portal. All employees must verify their banking information by Friday or payment may be delayed. Click here to log in."
Why it works: Payroll worries everyone and the deadline adds pressure. The link goes to a fake sign-in page.
Getting signed in doesn't mean it was safe. Some fake pages pass you through to the real Microsoft site after capturing your password, so nothing looks wrong. Never sign in through a link in an unexpected email. Type the address yourself.
Job & recruitment scams
Mostly targets students
Fake job offers that "select" you without an application, promise high pay for few hours, and eventually ask for your SSN, bank information, or Zelle transfers. Scammers pose as professors, department heads, and recruiters.
Read: Phishing — Job & Recruitment Scams →
How to spot phishing
When something feels off, stop and verify
- Check the actual sender address. Display names can say anything. A Gmail, Yahoo, or slightly altered NCU address is suspicious.
- Verify through a separate channel. If a message asks for money, credentials, or personal information, call the person using a number you look up yourself.
- Don't sign in through email links. Go to NCU systems by typing the address yourself.
- Urgency is a red flag. Pressure to act right now, especially about money or your account, deserves extra scrutiny.
- Deny MFA prompts you didn't start. Approving one is the same as handing over your password.
- NCU will never ask for your password by email, text, or phone.
Frequently asked questions
How did they get my email address?
Usually not from NCU's systems:
- It's public. Conference registrations, subscriptions, LinkedIn, and university web pages all expose NCU addresses, and automated tools harvest them.
- Other services get breached. Any platform you signed up for with your NCU address can leak it.
- Someone else's device was compromised. Malware on a colleague's phone or laptop can grab their whole address book.
- It can be guessed. NCU's email format is publicly known.
Getting a phishing email doesn't mean your account was hacked. It means your address is out there, which is true for almost everyone.
Why can't IT just block the sender?
IT blocks specific addresses when they're reported. But many phishing messages come from free services like Gmail or Yahoo, and blocking those entirely would also block students, vendors, and applicants.
These messages get through because they really do come from legitimate mail providers. Checking the sender address yourself is the most reliable defense.
The email says my account is compromised. Should I worry?
Probably not. "Your account has been compromised" is one of the most common phishing hooks, and it often isn't even about your NCU account.
If you're genuinely concerned, go to mysignins.microsoft.com yourself to review recent sign-ins, or call the IT Service Desk at 612.343.4170. Don't click anything in the email.
Reporting or responding
|
I received a suspicious message
|
I already clicked, signed in, or sent something
|
Don't click, don't reply. Report it:
- Outlook: select the message, then Report → Report Phishing.
- Outlook mobile app: tap … → Report Junk → Phishing.
- No Report button? Forward it as an attachment to incident@northcentral.edu.
Step-by-step: Reporting a Phishing Scam or Suspicious Email
|
|
What happens after you report: IT reviews every report. You may not hear back, since most are handled quietly. Campus-wide alerts go out when something is widespread.