Security

February 10, 2026

All about phishing: spotting the hook

Phishing is a type of social engineering attack where a threat actor tries to send an email, purportedly from a legitimate company requesting personal, financial, and/or login credentials.

What are some of the red flags of phishing? Threat actors try to use a combination of persuasive appeals across different dopics, but there are a few common threads:

  • Urgency: the attacker tries to get you to act quickly
  • Sensitivity: the attacker is trying to get personal or sensitive information
  • Secrecy: the attacker doesn’t want you to share what you’re doing with others (who might stop you)

They’ll try to use a combination of persuasive appeals: authority, scarcity, consistency, and/or reciprocity.

Category Example
Authority Hello are you available? Please I need your assistance urgently […] Department Chair Department of Ecology and Evolutionary Biology
Scarcity Transfer $700 to our bitcoin wallet […] A timer will start once you read this message. You have 48 hours to pay the above-mentioned amount.
Consistency Please excuse my late reply to your email from last week. Please click below to view your invoice: […]
Reciprocity The school is planning to surprise some of the students with gifts, and your confidentiality would be appreciated. I want you to make a purchase quickly on my behalf.

They’ll also try a wide spread of topics. These are just some examples, though they are common vectors.

Category Example
Security Your email account has been blocked, because you are required to re-verify your account.
Business logistics I used Dropbox to share some documents with you.
Job offers I am sharing a part-time job opportunity information from the World Health Organization (WHO) supply division with anyone interested, with a $500/weekly pay.
Need help Confirm if you are free? Need you to run a quick request. Get back to me as soon as you can.
Payment Your order on Delta.com website is now complete and your credit card has been charged.
Extortion I’m a programmer who cracked your email account and device about half year ago […] when you had fun on intime sites (you know what I mean!) I made screenshot with my program from your camera of yours device.
Signature needed Signed agreements have been sent using Dropbox file viewer on chrome. Press Here sign in with your email to view the approval.
Too good to be true Congratulations! We’re writing to let you know that you received Honorable Mention in yesterday’s article titled “Who’s Who in Academia”

Further reading

Want to learn more? Find out about lateral phishing and multi-stage phishing.

Citations

A. Pearson et al. Phishing Campaigns Targeting Higher Education Institutions. Google Cloud/Mandiant Threat Intelligence. February 24, 2025. [Online.] Available: https://cloud.google.com/blog/topics/threat-intelligence/phishing-targeting-higher-education/.

E. Morrow. “Scamming higher ed: An analysis of phishing content and trends.” Computers in Human Behavior, vol. 158, p. 108274. April 25, 2024. [Online.] Available: https://doi.org/10.1016/j.chb.2024.108274.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.