Phishing emails may lead you to click links, open attachments, or share sensitive data. If you've responded, take immediate action to limit risk.
If threatened or if you have been victimized by a scam, notify Public Safety (215-951-1300 or publicsafety@lasalle.edu).
1. Immediate actions
- Stop communicating with the sender.
- Do not click additional links, open attachments or reply again.
- If you entered a password, change it immediately from a device you believe is safe.
- If you opened an attachments or installed software, disconnect the device from the internet if it is behaving unusually. Contact La Salle IT Support for assistance.
- Report the phishing message (see below).
2. Report the Phishing Incident
Phishing messages are often sent to many people. Reporting the message allows the University to investigate it, block related messages, and warn others.
In Outlook:
- Select the suspicious message.
- Select Report or Report Message on the Outlook toolbar.
- Select Phishing.
- If the reporting button is unavailable, forward the message as an attachment to phishreports@lasalle.edu, or forward it as an attachment through the IT Support Portal.
Do not forward the message as a regular reply if doing so could expose confidential information. Do not delete the original message until La Salle IT Security and Compliance confirms that it is no longer needed for investigation.
3. Change Your Passwords and secure your accounts
Because malware can harvest your email and login credentials, change the password for your La Salle email account immediately if you:
- Replied with a password or other login information.
- Entered credentials on a website opened from the message.
- Reused the same password on another account.
- Clicked a link or opened an attachment and are concerned that your device may be compromised.
Use a different device that you believe is safe when possible. Change the password for your email account first because email is often used to reset other account passwords. Then change the passwords for any other account that used the same or similar password.
Use a unique, lengthy password for every account. A password manager can help create and store unique password.
After changing your password:
- Sign out of other sessions or devices, if the service provides that option.
- Verify that your recovery email address and phone number have not been changed.
- Confirm that multifactor authentication (MFA) is enabled and that no unfamiliar authentication methods were added.
- Contact IT Support immediately through the IT Service Portal or by calling (215) 951-1860 if you are locked out or cannot change your password.
- Run malware scan(s). (See below).
4. Scan the device for Malware
University-owned Devices
If you are using a La Salle University laptop or desktop, Do not install additional antivirus software on University-managed devices unless instructed by La Salle IT Department. Contact IT Support through the IT Service Portal or by calling (215) 951-1860 if you opened an unexpected attachment installed software, or entered login credential after clicking a suspicious link.
To run a scan using Microsoft Defender Antivirus:
- Select Start. (Blue Windows icon in bottom left corner)
- Type Windows Security in the search field, and open the app.
- Select Virus & threat protection.
- Under Current threats, select Quick scan.
For a more thorough scan:
- Select Scan options.
- Select Full scan.
- Select Scan now.
A full scan checks every file and program on the device. It may take considerable time.
If La Salle IT staff instructs you to run an offline scan:
- Open Windows Security.
- Select Virus & threat protection.
- Select Scan options.
- Select Microsoft Defender Antivirus (Offline scan).
- Select Scan now, save your work, and allow the computer to restart.
An offline scan runs after the computer restarts and before Windows fully loads. It is useful when persistent malware may be able to hide during a normal scan. To review results afterward, open Windows Security and select Protection history. Microsoft documents these scan options for both Windows 10 and Windows 11.
If a threat is detected:
- Follow the prompts to quarantine or remove it.
- Do not select Allow on devices unless La Salle IT Support or Security and Compliance staff confirms that the file is safe.
- Contact La Salle IT Support if the scan cannot complete, the threat returns, or the device continues to behave unusually.
Personal Windows Devices
Do not trust browser pop-ups or phone calls claiming that your computer is infected. Do not call a number shown in an unexpected pop-up. Open the anti-viruse software you installed on your device or Windows Security directly from the Start menu instead.
If you have other strong anti-virus software installed on your personal device, follow the scan instructions for that software. If you receive warnings about threats, ensure they come from your legitimate anti-virus provider. Follow your software’s guidance to quarantine or delete any infected files. If in doubt about a file, quarantine it; if that is not possible, delete it.
Keep Windows and your antivirus software updated. Microsoft Defender is built into Windows devices. To scan using Microsoft Defender:
- Select Start.
- Search for and open Windows Security.
- Select Virus & threat protection.
- Select Quick scan, or select Scan options then then Full scan.
If you suspect persistent malware, follow steps 1-3 above, then select Scan options, then Microsoft Defender Antivirus (offline scan). Save your work first because the computer will restart. Results are available under Protection history after the scan.
Personal Mac Devices
While macOS includes built-in security protections and are thought to be less susceptible to malware than Windows PCs, they can still be affected by malicious software. Install software only from trusted sources, keep macOS updated, and use reputable security software. Choose an anti-virus application from the Mac App Store, install it, and follow the prompts to run a system scan. If you opened an unexpected attachment, installed software, or notice unusual behavior, contact a qualified support provider. Do not provide payment or remote access to someone who contacted you unexpectedly.
5. Review Email Account, Including Forwarding Rules and Folders
Never include sensitive information in your emails or store emails that contain sensitive information. If an attacker accessed your account, they may use it to read messages, steal sensitive information, create forwarding rules, or send phishing emails from your address to your contacts, financial institutions, or other entities.
In Outlook on the web:
- Select View.
- Select View Settings.
- Select Mail.
- Review Rules and remove rules you did not create.
- Review Forwarding and remove unfamiliar forwarding address.
- Review Junk email, including blocked senders and Safe Senders.
- Review Sweep and Quick steps for changes you did not make.
The exact names and locations of these settings may vary by Outlook version or University configuration. Contact La Salle IT Support through the IT Service Portal or by calling (215) 951-1860.
Also check the following folders:
- Review Deleted Items folder for items you did not intentionally delete. This may be an indication that there are unintentional Rules set up on your account.
- Review Sent Items folder for email you did not intentionally send. This may be an indication that an attacker is using your email account to send phishing email.
- Also, review Junk Email, RSS Subscriptions, or other folders for unfamiliar emails.
If you find messages you don’t recognize, ask frequent correspondents if they received any suspicious communications from you after the incident.
6. Assess Exposure of Confidential Information
Email is not a secure method for transmitting sensitive information, yet it’s often used for this purpose. Review the suspicious message you received, your reply, and any website or attachment involved. Assume information may be compromised if you disclosed or entered:
- Social Security Numbers
- Credit, debit, or ATM card details (numbers, PINs, expiration dates, security codes)
- Bank or financial account numbers, ACH routing numbers
- Driver’s license or other government identification numbers
- Health insurance information (member IDs, provider numbers, group numbers, etc.)
- Passwords, login IDs, answers to security questions
- Tax documents, financial aid applications
- Employment, payroll, or salary data
- Personal contact information or answers used for account recovery.
Record what was disclosed, when it was disclosed, and which accounts or organizations may be affected. This information will help La Salle IT staff, your financial institution, and law enforcement respond.
If any of this information was included in your emails, assume it may be compromised and follow the precautions outlined below.
7. Take Action Based on the Information Disclosed
Passwords or account credentials
- Change the exposed password immediately.
- Change it anywhere else it was reused.
- Sign out of other sessions.
- Verify MFA and recovery settings.
- Report the incident to La Salle IT Support.
Credit or debit card information
- Contact the card issuer using the phone number on the card or the institution's official website.
- Ask whether the card should be blocked or replaced. In some instances, users may be able to place a freeze on credit or debit cards through the institutions official website or application.
- Review recent transactions and continue monitoring the account.
- Dispute unauthorized transactions according to the issuer's instructions. The Federal Trade Commission offers a sample dispute letter.
Bank account or routing number
- Contact your bank's fraud department immediately. Use the customer service or fraud reporting number printed on your card
- Ask what protections are available, such as account monitoring, an account change, or replacement checks.
- Monitor transactions and report anything unauthorized.
Social Security number or other identity information
- Obtain your credit reports from AnnualCreditReport.com.
- Review them for unfamiliar accounts, inquiries, addresses, or other activity.
- Consider placing a credit freeze with all three nationwide credit bureaus. A freeze is free and remains in place until you remove it.
- You may instead place a free initial fraud alert by contacting any one of the three credit bureaus. That bureau must notify the other two. An initial fraud alert generally lasts one year.
- Report identity theft and obtain a recovery plan at IdentityTheft.gov.
- Report suspected criminal activity to local law enforcement and/or La Salle Public Safety when appropriate.
Telephone number or mobile account information
- If you provided your cell phone number and receive suspicious calls or texts, block the number.
- Do not respond to unexpected calls or text messages.
- Contact your mobile carrier if you suspect an attempted SIM swap or unauthorized account change.
- Add or confirm an account PIN or other carrier security control.
Health, student, employee, or University information
Contact La Salle Public Safety, Registrar, Student Financial Services, Human Resources, Payroll, or Information Security and Compliance office(s) as appropriate using the contact information located in the Directory in the University (mylasalle) portal. Do not send additional confidential information by replying to the phishing message.
8. Monitor for follow-up activity
For at least several weeks, monitor:
- Email sign-in alerts and password-reset messages.
- Bank and credit-card accounts.
- Credit reports.
- Mobile-phone account activity.
- University account activity.
- Messages sent from your email account.
- Unexpected mail, bills, or account notices.
Do not click on links contained in alerts unless you have verified that it is from the legitimate source. It is better to log into accounts using the official website or application.
If you discover fraudulent transactions, file reports with the Federal Trade Commission, FTC Identity Theft, your local police, and the FBI’s Internet Crime Complaint Center (IC3). Cases of Identity Theft should also be reported to FTC's IdentityTheft.gov
Keep copies of the original message, headers if available, screenshots, transaction records, and communications with service providers. Do not alter suspicious files or messages if La Salle IT Security and Compliance staff or law enforcement asks you to preserve them.
9. Reduce the Risk of Future Phishing Incidents
- Use MFA, preferably a passkey or authenticator app when available.
- Use a unique password for every account.
- Use anti-virus software with real-time protection and run regular scans.
- Keep Windows, macOS, browsers, applications, and antivirus software updated.
- Use a standard, non-administrator account for routine work when possible.
- Treat unexpected requests for payment, credentials, gift cards, or confidential information as suspicious
- Verify requests through a separate, trusted communication channel.
- Do not use contact information or links supplied in the suspicious message.
- Before selecting a link, inspect its destination. On a computer, hover over the link; on a mobile device press and hold only when it is safe to do so.
- Do not open unexpected attachments.
- Do not rely on spelling, grammar, logos, signatures, or generic greetings alone. Attackers can imitate legitimate organizations and may use polished writing.
- Report suspicious messages using the University's approved reporting method.
10. Common Signs of Phishing
A message may be phishing if it:
- Creates unusual urgency or pressure.
- Requests a password, MFA code, payment, gift card, or confidential information. Reputable companies rarely ask for sensitive information via email. Call the company using a verified phone number to confirm suspicious requests.
- Contains an unexpected attachment or link.
- Uses a sender address that is similar to, but not the same as, a legitimate address. Confirm the sender’s address is legitimate and correctly spelled
- Asks you to bypass normal procedures.
- Claims to be from a supervisor, vendor, bank, government agency, or University office but uses unusual contact method.
- Requests secrecy or discourages independent verification.
When in doubt, stop and verify the request using a known phone number, a new browser session, or a separate message to a trusted contact. Trust your gut: If something feels off, confirm the email’s legitimacy or report it.
Report suspicious emails: Use the “Report Message” tool in your email toolbar to alert IT of any potentially dangerous emails.