Skip to main content

IT security scam of the week: Bogus performance reviews used as phishing bait

Beginning this month, Information Technology (IT) Services will share short IT security tips and tricks, details about current phishing scams and other security-related information the university community should be aware of.

This week’s tip: Bogus performance reviews used as phishing bait

Beware: scammers are using fake job performance reviews to trick you into giving up your username and password.

Here’s how it works:

The scammer sends you an email that appears to come from your Human Resources department. The email contains a link to a fake website where you are instructed to log in so you can receive information about your performance review. If you enter your login credentials here, the attackers will have access to your account, and your entire organization could be compromised. 

Remember: Never click on a link you weren't expecting to receive, even if it appears to be from an internal team member or someone you know. It's best to pick up the phone and verify that the email is legitimate before putting yourself and your company at risk.

Don’t be fooled; stop, look and think before you click!