RIT Information Security

RIT Information Security Stay ahead of digital threats with our expert tips & safeguarding RIT’s information resources.

The Information Security Office provides strategy definition, risk assessment, standards development, communication & training, and investigation of threats & incidents.

💰 $400 a week. Easy remote work. No qualifications needed. Too good to be true — and it was.Great catches in the comment...
08/04/2026

💰 $400 a week. Easy remote work. No qualifications needed. Too good to be true — and it was.

Great catches in the comments! Here are the 5 red flags that expose this fake job offer 🔍

🚩 1. Sent from a compromised RIT account — The .edu address was real but hacked. Scammers use legitimate accounts to bypass spam filters. Always verify job offers through RIT’s official Career Services portal. ✅

🚩 2. Grammar and capitalization errors — “Liaise” randomly capitalized, awkward phrasing throughout. Professional job postings are carefully proofread. ✍️

🚩 3. Vague job description — “Basic admin duties” with zero specifics, no qualifications, no application process. Legitimate roles always include clear details. 📋

🚩 4. Asks for your alternative email address — Moves the conversation off your secure RIT email to avoid university security monitoring. This is how the scam escalates — often leading to fake check fraud. 📧

🚩 5. ‘Senior Investment Director’ signing off on an admin job? — The title has no connection to the role described. A classic sign of a scam template copy-pasted across hundreds of student inboxes. 🤔

📧 Received a suspicious job offer? Report it immediately to [email protected]

Always Remember — always verify student job opportunities through RIT’s official Career Services portal before responding to any unsolicited email.

awareness

💸 A job that pays $400 a week for basic remote admin work — and it landed in a student’s RIT inbox.Sounds tempting, righ...
08/03/2026

💸 A job that pays $400 a week for basic remote admin work — and it landed in a student’s RIT inbox.

Sounds tempting, right? Especially during a busy semester. 📚

But something about this email isn’t adding up. 🚨

👀 Take a close look — how many red flags can you find? Drop your answers in the comments below ⬇️

🕐 The full breakdown posts in 24 hours.

🔍 Great catches in the comments — this one had 5 red flags, and it’s a type of attack called “Quishing” — QR code phishi...
07/28/2026

🔍 Great catches in the comments — this one had 5 red flags, and it’s a type of attack called “Quishing” — QR code phishing.

Here’s the full breakdown of what gave it away:

🚩 1. Sent from [email protected] — RIT IT will NEVER contact you from a Gmail address. All legitimate RIT emails come from .edu only. ❌

🚩 2. Typo in the sender name — “Cantact Support” instead of “Contact Support.” Spelling errors are a classic sign of a hastily crafted phishing attempt. ✍️

🚩 3. Sent to undisclosed recipients — RIT will always address you personally and email you directly. Mass BCC campaigns to hidden recipients are a huge red flag. 👥

🚩 4. QR code instead of a link — Attackers use QR codes because email security tools cannot scan where they lead. Never scan a QR code from an unexpected email. 📵

🚩 5. Vague urgency with no specifics — “Recent security activities” — what activities? Legitimate IT alerts always include specific details, ticket numbers, or direct contact info. 🤔

📧 If you receive something like this, do NOT scan the QR code. Report it immediately to [email protected]

Next week: another scenario. Stay sharp. 👁️

📲 You get an email asking you to scan a QR code to update your Two-Factor Authentication.It has the RIT name. It sounds ...
07/27/2026

📲 You get an email asking you to scan a QR code to update your Two-Factor Authentication.

It has the RIT name. It sounds urgent. It even mentions IT Services. ⚠️

But before you point your camera at that QR code — take a close look at this email. 👀

🚩 How many red flags can you spot? Drop your answers in the comments below ⬇️

🕐 The full breakdown posts in 24 hours.

⚠️

✅ Great catches in the comments — this one had 6 red flags, and it was 100% real.Here’s the full breakdown of what gave ...
07/20/2026

✅ Great catches in the comments — this one had 6 red flags, and it was 100% real.

Here’s the full breakdown of what gave it away 🔍
🚩 1. Sent from a student email — RIT IT never contacts you from a student account.
🚩 2. Mass-sent to 191+ recipients — legitimate university emails are never bulk-blasted like this.
🚩 3. “24-hour deactivation” threat — pure pressure tactic to stop you from thinking before clicking. ⏰
🚩 4. The linked form asked for your password, Student ID, date of birth, and BankMobile credentials — RIT will never collect this via a Google Form. 🔐
🚩 5. “Send-only, unmonitored account” — why would an urgent official notice come from an account no one reads? 🤔
🚩 6. Signed by two different offices — Financial Services AND Public Relations. No real university email does this. ❌

📧 If you received something like this, report it immediately to [email protected].

InfoSec StudentSafety

🎣 This email actually landed in some RIT student inboxes recently.It looks official. It has the RIT logo. It mentions yo...
07/16/2026

🎣 This email actually landed in some RIT student inboxes recently.

It looks official. It has the RIT logo. It mentions your financial aid. It threatens account deactivation in 24 hours. ⏳

But something is seriously wrong with it. 🚨

👀 Take a close look — how many red flags can you find? Drop your answers in the comments below. ⬇️

🕐 The full breakdown posts in 24 hours.

✅ Great catches in the comments — you spotted the key red flags.🚨 Here is a breakdown of the 4 signs that give this phis...
07/09/2026

✅ Great catches in the comments — you spotted the key red flags.

🚨 Here is a breakdown of the 4 signs that give this phishing email away:

1️⃣ 🌐 Fake sender domain — the email came from rit-edu.helpdesk.net, not rit.edu. RIT will never contact you from a third-party domain.

2️⃣ ⏳ Artificial urgency — “48-hour processing delay” is a classic pressure tactic designed to stop you from thinking clearly before you click.

3️⃣ 🖱️ Suspicious call to action — no legitimate financial aid office will ask you to “verify banking details” by clicking a link in an email.

4️⃣ 📧 Reply mismatch — the email says “do not reply” but provides a different contact address. Both are fraudulent.

🛡️ If you ever receive an email like this, do not click any links. Report it directly to [email protected].

👀 Next week: a different scenario. Stay sharp.

RIT StudentSafety

🎣 This email landed in student inboxes recently — and it looks convincing at first glance.💸 A “financial aid disbursemen...
07/08/2026

🎣 This email landed in student inboxes recently — and it looks convincing at first glance.

💸 A “financial aid disbursement” of $3,840.
⏰ An urgent deadline.
🔵 A big blue button.

🔍 Before you click anything, take a close look. How many red flags can you find in this email?

💬 Drop your answer in the comments. We’ll post the full breakdown in 24 hours.

⚠️ Phishing attacks on universities spike at the start of every semester — when students are expecting tuition updates, aid disbursements, and enrollment confirmations. That timing is not a coincidence.

A newly revealed flaw in WhatsApp and Signal allows attackers to silently track users in real time and even drain their ...
12/17/2025

A newly revealed flaw in WhatsApp and Signal allows attackers to silently track users in real time and even drain their phone batteries and data. Security researchers warn that by exploiting delivery receipts and measuring round‑trip times, adversaries can monitor over 3 billion users worldwide simply by knowing their phone number, uncovering details such as when someone is home, asleep, or actively online—all without triggering notifications. The vulnerability, dubbed Silent Whisper, highlights a fundamental weakness in the messaging protocols and raises urgent concerns about privacy and resilience against stealth surveillance.
Read more here;

A publicly released tool can exploit a vulnerability in WhatsApp and Signal’s delivery receipts to secretly track the real-time activity of over three billion users, while also draining battery and data.

12/16/2025

Make sure to always check those emails for spelling errors and grammar mistakes! Theyre a common sign that the email is spam or phishing you!
Here are a few ways you can protect yourself:

Check the email address carefully: Phishers often use addresses that look similar to legitimate ones (e.g., [email protected] instead of [email protected]).

Hover over links before clicking to see the actual URL destination. If it looks strange or doesn’t match the sender’s domain, don’t click.

Be cautious with urgent messages claiming your account will be locked or that you must act immediately. Phishers rely on panic to trick you.

Address

1 Lomb Memorial Drive
Rochester, NY
14623

Alerts

Be the first to know and let us send you an email when RIT Information Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to RIT Information Security:

Shortcuts

Share