Helping protect the University from phishing attacks

Cyber-attacks against organisations like ours are getting more complex, and you are the first line of defence in helping keep the University teaching students and undertaking research, as well as keeping your own data safe.

Colleagues at the University have received many different styles of phishing emails. These can range from a fake Microsoft document sharing link to a fake invitation to collaborate on an academic paper from an international institution.  

Whilst the University has implemented technical security protection mechanisms, we can all act as human firewalls by being vigilant and proactive. The Marks & Spencer cyber-attack started with social engineering; your help is critical to defend the University from a similar fate. 

What to look out for: 

  • Be wary of emails that create a sense of urgency, contain suspicious file links with a poor description, or come from unfamiliar senders.  
  • Be wary of Microsoft document sharing emails, attachments, and links. Treat all attachments and links with caution. If someone shares a document with a generic description or no description, then ask them in person or via Microsoft Teams if they intended to share this document. 
  • Do not automatically trust emails from people you know. Always check links by hovering over them, as compromised accounts are frequently used to abuse trust. 
  • Politely challenge unusual requests. This could be a potentially fake email asking for an iTunes voucher to be obtained on a Purchasing Card, or an external telephone call asking who is responsible for Finance System access.  

IT Services work tirelessly to keep phishing attempts out of our inboxes and protect our digital infrastructure, but cybersecurity is a shared responsibility. 

The University has asked IT Services to undertake a simulated phishing campaign during the 2026/27 academic year to give colleagues the opportunity to practice these steps in a safe environment with supportive training. 

If you click and respond to the simulated phishing email, there will be no punitive repercussions. You will be told straight away what has happened and will be asked to take a brief online phishing training module. 

By working together and staying vigilant, we can protect ourselves and our University from cyber threats.