A new academic year brings new routines, classes, and meetings. As you quickly scan a crowded inbox, a subject line catches your attention: “Your Office 365 account has been terminated.” The message directs you to click now and enter your HawkID and password. If you’re unprepared, this clickbait title may leave your account vulnerable to a cybersecurity risk.
Social engineering scams work by catching capable people at busy moments. Scammers borrow familiar logos, names, job titles, and campus language, then use fear or opportunity to hurry you to the next click. They’re built to inspire urgent action and are often difficult to scroll past. View examples of previous phishing attempts.
The account emergency
A message may claim your Microsoft 365 account has been terminated, exceeded its storage limit, or requires immediate verification. The link leads to a convincing sign-on page designed to capture your HawkID and password and may be followed by an unexpected Duo prompt to verify your identity. Phishing messages even may try impersonate UI support or other departments.
If you’re concerned that the message might be a phishing attempt, close it. Open the website service from a trusted bookmark or type the known URL address in a browser yourself.
The ‘perfect’ side hustle
An unexpected recruiter offers flexible remote work, serving as a personal assistant, rating products, liking videos, depositing a check, or buying equipment. The pay sounds generous, and the interview may happen entirely by text. Then comes the twist—you must pay a fee, purchase gift cards, move money, deposit a check and return part of it, or provide bank or identity information.
A legitimate employer will never ask you for payment or for use of your bank account. To verify if a job opening is legitimate, look on the employer’s official website and contact the organization independently.
Give yourself 10 seconds to consider the next step
Before clicking, replying, or approving a Duo notification:
- Pause. Urgency is a tactic, not a deadline.
- Inspect. Learn how to check the full sender address and find a link’s real destination.
- Verify. Contact the person or office using a known number, directory entry, or official website.
- Avoid. Never send a password by email or approve a Duo prompt you did not initiate.
- Report. Your report may stop the same message from reaching someone else.
In Outlook, use the Report Message, or forward suspicious email as an attachment to ui-phishing@uiowa.edu. If you clicked, entered credentials, approved an unexpected Duo prompt, or suspect a compromise, immediately contact your local IT support or the ITS Help Desk or HCIS Help Desk.
Report all IT misuse, compromises, and disclosures of sensitive or personal information to the Information Security and Policy Office (ISPO) at it-security@uiowa.edu or 319-335-6332. Campus partners may also contact ISPO for guidance tailored to business, teaching, research, or operational needs.
Protecting yourself is not about spotting every scam instantly. It is about giving yourself permission to pause, verify, and ask for help.