Learn about email security including identifying fraudulent emails, email encryption, and more.
How to Identify Fraudulent Emails
Cyber criminals use compelling email messages to trick you into clicking a link, downloading an attachment, or replying to an email. Once you have reacted to their message, they steal sensitive information or install malicious software on your computer.
When interacting with email, do not rely on any single approach to identifying a scam, know all the possible signs (especially #4):
An urgent subject line, language prompting you to act quickly.
A direct email you were not expecting (even if it appears to be from someone you know, or someone at Ļć½¶Šć).
- Be aware, occasionally a legitimate Ļć½¶Šć email account is hacked, and used to send scam emails to other Ļć½¶Šć community members.
āFromā addresses with sneaky variations of (legitimate) email addresses. Examples: Ending in @bc-edu.org instead of @bc.edu
- Get in the habit of checking the from/signed by. See below for details.
- Messages from a Ļć½¶Šć person or department that do not have an @bc.edu in the email address should be viewed with extreme skepticism.
- A sender name is easy to fake.
- If you arenāt sure if an email is authentic, instead of replying, contact the sender using information you already have about them (such as their Ļć½¶Šć email address from the Ļć½¶Šć Directory).
Ģż
How to Verify the Sender Email Address in Gmail
- Next to the Sender Name, click the down arrow to view more sender information.
- Review the actual From Email Address located inside the angled brackets.
- Example: Ļć½¶Šć Help Center <help.center@bc.edu>
- Review the ās¾±²µ²Ō±š»å-²ś²ā:ā and verify the domain it was sent from is what youād expect. It should match the portion of the email address that follows the ā@ā in the From Email Address.
What about hacked accounts? Beware. If someone's email account has been compromised, it may be used to send malicious emails. So even if a sender email address appears authentic, always be cautious if an email has any of the other warning signs that it could be a scam.
- Never click on an attachment you were not expecting. You could unknowingly download a virus or ransomware to your device.
- Just because it looks like a Ļć½¶Šć sign in page doesnāt mean it is!
- Any link that takes you to a form that looks like the Ļć½¶Šć sign in page BUT has a non-Ļć½¶Šć web address, is a SCAM.
- Ļć½¶Šć will NEVER ask for a password unless it is on an official Ļć½¶Šć login screen. Official login screens always have bc.edu before the first single, forward slash (/), for example:
https://login.bc.edu/nidp/idff/sso?id=19&sid=0&option=credential&sid=0
- Just because it looks like a Google sign in page, doesnāt mean it is!
- Scammers also create log in pages that look like Google log in screens, but arenāt! Instead they are just hoping to steal your credentials and access your Google account.
- Official Google log in screens always have google.com before the first single, forward slash (/), for example:
https://accounts.google.com/v3/signin/identifier?authuser
=0&continue=https%3A%2F%2Fmail.google.com%2Fmail&ec
=GAlAFw&hl=en&service=mail&flowName=GlifWebSignIn&flowEntry
=AddSession&dsh=S606954128%3A1728478423789165&ddm=1
https://docs.google.com/document/d/1uIGZq3yh5sE_d9N-fA4GOZKO5zxrwMGaEKyUHtcA4hY/edit
- Hovering over a link to see the web address can helpful. However, many departments on campus use third party email marketing tools to send messages, which can cause a link to a legitimate web page to look like āhttps://t.e2ma.net/click/p0obxi/lt0szkrb/haz7huā. In those cases, when it doubt, go to www.bc.edu website and search for the information mentioned in the email.
Typos, odd phrasing, unnecessary capital letters are often indicators of a scam.
Ģż
Official Ļć½¶Šć emails will not have QR codes in the body.
Ģż
What to do if you receive a fraudulent email
- Do not reply to the email, or text/call any phone numbers included in the email.
- Do not click on any links or attachments in the message.
- Forward the original email message* to: phishing@bc.edu
You will receive an AI-designedĢżfollow-up email letting you know if the email was malicious, safe, spam, or phishing simulation. As AI is an experimental tool, you may occasionally receive an incorrect assessment.
- If possible, in Gmail, click the three dots in the upper right corner and select, āReport phishingā or āReport spam.āĢż
Ģż
* What not to forward to phishing@bc.edu
In order for the email security tool to give you an assessment:
- Do not forward screen shots of emails or text messages
- Do not forward emailsĢżwith additional text
- Do not forward emails that werenāt received by you directlyĢż
Ģż
Avoid Your Spam and Trash Folder
Messages in Spam and Trash folders were automatically moved out of your Inbox because they were identified as spam or phishing. They may contain malicious emails, so please avoid reading or interacting with messages in these folders. Only check Spam and Trash if you're expecting a message that hasnāt arrived in your Inbox. There is no need to report messages found in these folders to phishing@bc.edu.Ģż
Ģż
Think You've Been Compromised?
Report a Security Incident
If you think youāve been the victim of a phishing email, emailĢżsecurity@bc.eduĢżto report it. A member of the IT Security team will follow-up with you.
Protect Your Account
- Change your Ļć½¶Šć Password and Ļć½¶Šć Gmail Passwords.ĢżPhishing emails often target your credentials so they can access your email account, or your Ļć½¶Šć account, and gain access to your private data. Change your passwords, and take away their access.
- Change other passwords. If you use your Ļć½¶Šć passwords on any other accounts, change those passwords as well.
- Log out of all other Gmail Sessions. If a bad guy got a hold of your Ļć½¶Šć Gmail login, they may be logged into your account. Kick them out! In the bottom right corner of Gmail, click Details and then Sign out all other web sessions.
- Check your Sent Mail folder.ĢżBad guys often use compromised email accounts to send malicious messages to others in your contacts. If you see emails were sent from your account which you did not send, this would confirm your account has been compromised, and will let you know who has received an email from your account.
- Check your mail forwarding settings.ĢżBad guys often enable mail forwarding, so messages sent to your email will be forwarded to an account of their preference. Disable unwanted email forwarding by going to Settings > Forwarding and POP/IMAP > Disable forwarding > Save.
- Check your Google email settings and remove any suspicious accounts.ĢżGo to Settings > Accounts > Send Mail As.
- Report the email as phishing in Gmail. Learn .
- Scan your computer for malware or viruses.
Email Security
Electronic Abuse
While Boston College strives to provide an open computing environment to foster collaboration and learning, there are policies defining appropriate use of the Ļć½¶Šć network and computing resources, such as email. Before reporting electronic abuse, make sure you are familiar withĢżĻć½¶Šć's computing policies and guidelines.
Examples of Electronic Abuse and Appropriate Action to Take
- Your system/server has been or is being attacked: Report the abuse immediately and do not make any changes to the system until you hear from the ITS security team on campus. You may accidentally remove vital information that can be used as evidence.
- You received offensive or threatening email or voicemail: Do not delete the offensive message as it can be used as evidence.
- You suspect someone knows or is using your Ļć½¶Šć password: Report the compromise immediately with any substantiating evidence. Change your password immediately.
- You are aware of software copyright violations at Boston College.
Report Electronic Abuse
Send an email to abuse@bc.eduĢżdescribing the electronic abuse. You must show the full message headers of any email message that you are forwarding. Do not delete the email from your inbox until you have heard back from us.
Encrypted Email with Virtru
If you need to send confidential emails as part of your job, you may want to consider requesting Virtru. Virtru is an email security tool that allows you to:
- encrypt emails
- prevent a forwarded encrypted email from being read
- set a read expiration date on encrypted messagesĢż
- and revoke the ability to read an email after it is sent
Ģż
Getting Started with Virtru
If you think you may need this service, contact your Technology Consultant. Once approved, install Virtru for Gmail or Outlook. Ģż
Email recipients do not need to install Virtru to read or respond to your email. Recipients of an encrypted email will not be able to access the message directly from their inbox. Rather, they will be prompted to "unlock" the message, and verify their email address.
ITS recommends you inform your recipients to expect an encrypted email, since they will be prompted to take extra steps to unlock the message. The best way to do this is to add a customized intro to your message.ĢżBe sure to include information that only your recipient would know, or write it in such a way that they know it's really you.
Partially.ĢżYou can install the Chrome plug-in, which will allow you to decrypt and respond to any Virtru messages sent to you. However, you will not be able to initiate a Virtru encrypted email.
Email Security Service
Ļć½¶Šć employs an email security service integrated with Ļć½¶Šć's Gmail to safeguard against malicious emails. This AI-powered service automatically detects and eliminates threats like phishing, malware attachments, and business email compromises. Additionally, it complements Gmail's existing spam filtering to further minimize the number of harmful emails reaching your Ļć½¶Šć inbox.
What to Expect
- The majority of emails identified as threats are automatically moved to your Ļć½¶Šć Gmail Spam folder.
- Emails identified as āAdvanced Attacksā are automatically moved to your Gmail Trash. If you actively monitor your Inbox, you may see a message (that has been deemed a threat) appear, and then disappear within seconds.
- Although this service will reduce the number of email threats, it is still imperative to be mindful when you receive suspicious emails.
- Rarely, this service may inadvertently flag a legitimate email as malicious. If you think this has occurred, please check your Spam folder and Trash. If you find a message in your Spam or Trash that should not have been there, please report it to the Ļć½¶Šć Technology Help Center so they can address the issue and prevent similar messages from being moved incorrectly.
Ģż
Questions?Ģż
Contact the Ļć½¶Šć Technology Help Center for assistance at help.center@bc.edu or (617) 552-HELP (4357).Ģż
Boston College implemented a Phishing Simulation program to increase awareness and education related to phishing emails, therefore decreasing the risk of exposure of University data.ĢżPhishing simulation is ongoing for all students and for select faculty and staff, by department request.
Why is Ļć½¶Šć Doing This?
Colleges and universities continue to report increased phishing incidents in which bad actors try to trick people into clicking on malicious links in an effort to steal passwords, access personal or University data, and in some cases encrypt data and demand money for the data to be unencrypted.
Sample Phishing Simulation Educational Web Page
If you mistakenly click on a phishing simulation email link or attachment, you will be taken to a web page thatĢżexplains which characteristics of the email were clues of a typical scam.
Sample Phishing Simulation Email
