Phishing, Smishing, and Vishing
Should you trust that email, text message, or call?
Malicious actors can use emails, text messages, or calls to attempt to steal personal or private information. These messages or calls are crafted to seem legitimate but are actually used to capture sensitive information, which can put you and the university at risk.
Here are some warning signs to look out for:
- Language that creates a sense of urgency or ultimatum
- Request for upfront payment (even if it appears to be from a “trusted” person)
- Request for sensitive information like usernames and passwords
- Slightly modified email addresses or unknown mobile numbers
- Out of context requests
- Bad grammar, punctuation, or spelling
- Links with no clear destination or links to unfamiliar websites
- QR codes
Level up your defense: Read more on phishing scams
ClickFix Campaigns
Is that website really trying to help you?
ClickFix is a social engineering tactic that uses fake technical issues or human-verification prompts to trick you into copying and executing malicious commands. This user-assisted attack bypasses traditional security and can instantly infect your device with malware.
If you encounter a website pop-up urging immediate action, simply close the page or tab.
Look out for these red-flag instructions:
- Press the Windows key + R
- Open PowerShell, Terminal, or Command Prompt
- Copy and/or paste this code
- Run this to prove you’re not a robot
- Install this update or extension to continue
Remember: Always use built-in system settings for updates and never run commands you don't fully understand. UCR Information Technology Solutions (ITS) and legitimate companies will never ask you to paste commands from a website.
Dig deeper: Learn how ClickFix and FakeUpdate campaigns work
Job Scams
Was the job offer you received the real deal?
Job scams are a type of email scam wherein the attacker impersonates someone from UCR or other legitimate companies and tricks their targeted victims into sending money or providing sensitive information.
Using social engineering tactics, the attacker may ask students to send resumés, bank account numbers, social security numbers, addresses, birthdays, research data, gift card codes, etc.
Here are the red flags to watch out for:
- Pressure to act fast
- No company name provided
- Promise of high payment for a minimal amount of work
- Being asked to open an email attachment in order to view the job offer
- Offers to send money
- Requests for money or gift card codes
- Requests to communicate through non-UCR channels (text message, non-UCR email, other applications, etc.)
- A job offer you did not apply for
- Awkward sentence phrasing and spelling or grammar errors
Apply for legitimate UCR jobs: Visit UCR Handshake
Report A Security Concern
UC Riverside is a prime target of cybercriminal attacks such as phishing, ClickFix campaigns, job offer scams, and ransomware.
If you notice suspicious activity on your UCR account, computer, tablet, or mobile device, please report it immediately to the ITS Information Security Office.
Want to make sure your data is safe, but don't know where to begin?
This video provides simple steps you can take towards making sure your data is secure.
Request A Consultation
The ITS Information Security Office is your partner in data security.
If you are looking for cybersecurity resources, unit-specific data, or security policy information, please send us an email.