Phishing attacks: How to recognize scams and protect your information

University Police Department-Northern Command gives tips and advice for keeping your information safe

Students working on computers in a computer lab

Learn how to stay cyber safe.

Phishing attacks: How to recognize scams and protect your information

University Police Department-Northern Command gives tips and advice for keeping your information safe

Learn how to stay cyber safe.

Students working on computers in a computer lab

Learn how to stay cyber safe.

What are phishing attacks?

Phishing attacks are a common form of cyberattack aimed against higher education students, faculty and staff members. They ask for personal information, financial information and sensitive data. Phishing emails will impersonate professors or university faculty, organizations or university departments. Often, they will try and provoke an immediate response to send sensitive information or offer an entity too good to be true. 

Trends in phishing attacks

With artificial intelligence (AI) in full force, phishing emails have seen a significant increase in 2026. In 2025, $302 million was reported lost to cybercrime in Nevada, ranking 3rd in the nation for per-capita losses. Phishing emails commonly target students, often offering a job/research position or a giveaway such as an electronic device or money. Many emails contain a phone number or QR code that ask you to further communicate with the sender so that the University can no longer track the email activity. Scams may also ask for University or personal login credentials to gain access to protected information.

How to recognize a phishing attack

Phishing emails will try to impersonate a University member through the use of their name with an external email address. All emails from the University of Nevada, Reno, will only come from @unr.edu. Some scams can still come from @unr.edu, falsely impersonating someone asking for money or a response within 24 hours. Any emails from @gmail.com or @hotmail.com will never be used by university faculty to offer a job position or contact a student for any reason. Never click on any URLs sent from these emails. 

What to do if you receive a phishing email

All phishing emails should be reported to abuse@unr.edu. The Office of Information Technology (OIT) will review the email and let you know whether or not the sender is legitimate. Immediately delete the email; do not respond or retaliate. Everyone has a responsibility to not only protect their personal IT assets and information but also the University’s data and IT infrastructure. All other questions or security concerns that do not involve an ongoing phishing attack should be sent to soc@unr.edu.

What to do if you already responded

If you have already interacted with the suspicious email, immediately cease contact with any source related to the phishing attack. Report the email to the security operations center in OIT at abuse@unr.edu.

Please include details such as what information was provided, as well as whether or not you clicked/interacted with this email on a University-owned device. OIT will be able to provide you with more detailed information as to next steps with that information. If you interacted with it on a University-owned device, please be prepared for your device to be reimaged if necessary. This is a necessary step in most malicious-link interactions, as phishing links can and often do harbor malware alongside compromising credentials. Once a ticket is created by us for a device reimage, please make time for an IT staff member to come pick up and drop off your device. Also report any phishing attacks to the University Police Department through the UPD website or in person in the Fitzgerald Student Services Building. 

“Email scams continue to evolve, and unfortunately, they are becoming more convincing,” Joshua Reynolds, deputy chief of police for University Police Department-Northern Command, said. “Scammers often create messages that appear to come from legitimate businesses, government agencies, financial institutions or even someone you know. We encourage people to slow down, look closely at the sender and the request, and never provide personal, financial or account information simply because an email asks for it. When something feels urgent or unusual, take a moment to independently verify the request before taking action. A few extra seconds of caution can prevent a significant financial or personal loss.”