Skip to main content

Scarsdale Public Schools

Learning, Living, Leading

Phishing Information

How to Spot and Report Phishing

Please read the caption beneath each image to learn more about the phishing attempt. If you would like additional hands-on practice, please take the Google Phishing Quiz. If you see a suspicious email, please forward it to privacy@scarsdaleschools.org for review. Thank you for your help to identify and reduce the spread of phishing emails. 

 

**New phishing techniques don’t need your username and password, clicking on the link can be enough to give someone else access to your account. Please be cautious about clicking any suspicious or unknown links. 
 

  • Fake estate or moving sale email with list of suspiciously low-priced vehicles.
    Fake estate or moving sale email. The email lists several used cars for below market value. People who respond to the email will be asked to put down a deposit to hold a vehicle. The goal is to collect deposits from victims.
  • Fake email confirming subscription to an unknown service or confirming purchase of an unknown product.
    Fake confirmation purchase email. The goal is to get a person to call the phone number in the email. Victims are asked to provide credit card information to "confirm" identity, which results in the theft of card details.
  • Malicious Google Drive share email which contains a link to a .docx document with malware or credential theft.
    Malicious Google Doc shared by someone outside of the organization pretending to be a school employee. The file, often a .docx, contains malware or will redirect to a fake login page intended to steal email and password.
  • Fake email from superintendent or human resources asking for new employees to provide cell phone number.
    Fake email from HR or the superintendent asking for a new employee's cell phone. The intention is to get the employee out of "official" channels to pressure them to take action, send gift cards, or share data.
  • Fake party invitation from punchbowl inviting guest to special dinner party.
    Fake party invitation, typically from Punchbowl or Paperless Post, to a generic special invitation or party without details. The evite link will lead people to a fake login page to collect username and password or it will lead to a malicious download.
  • Fake CAPTCHA image, known as ClickFix, that prompts user to install malware.
    Fake CAPTCHA image, known as ClickFix, that prompts you to download and install malware. If you see a site with this image, report it to the tech department so it can be blocked on the Scarsdale network.