Body
It's no secret that compromised accounts are the leading cause of cybersecurity incidents, and email phishing is responsible for the vast majority of compromised accounts. Middlebury's email security filters are very good, however the bad actors behind these malicious messages are relentless in their attempts to gain access to our Middlebury accounts, and occasionally a cleverly crafted phishing email can slip through the gates. To help our community better spot them, we are launching a new email phishing simulation program. Every month, a real-looking, yet simulated phishing email will arrive in your inbox, helping you become more familiar with common tactics.
-
What to expect: Every month, you'll get one realistic, simulated phishing email. It's completely safe, and the goal is simply to help you get familiar with the tactics real attackers use.
-
If you spot it: Report it right away. Use your email client's report button. There's no need to forward the email, the report button alerts ITS to the message AND automatically looks for similar messages in our environment. Please do this for ANY message you think may be phishing, including these simulations.

-
If you interact with it: You will get a short, customized training link. Please complete the training and let us know if you have any questions about the material, as it is crucial that we, as a community, learn how to spot these attacks and avoid becoming a victim.
Our goal is not to penalize any community member who clicks on an email phishing link, but rather to start a conversation about the risks involved in email phishing and to provide tips for preventing account compromises. If you did click on the link, your account is secure, and there is no need to change your password at this time. You will be assigned a brief online training module. In addition, we recommend you take a few moments to review the information below on how to spot phishing attacks.
How to Spot Phishing Emails:
When you're unsure whether an e-mail is legitimate, ask yourself these questions:
- Do I normally receive messages from this person?
- Am I expecting to receive a message from this person?
- Does the message that this person sent line up with messages they typically send me?
- If you know the person well, does the email sound like something they'd write? (Grammar, spelling, tone)
- Is the person asking you to do something with a sense of urgency?
- Is the person asking you to do something related to a financial transaction?
Phishing webpage clues:

- Watch the URL bar in the top of the browser window, phishing pages will have a random URL that is not a Microsoft webpage
- Some URLs may be close to what you'd expect, but have slightly different spelling. For example: http://www[.]m1iddlebury[.]edu