Bonus Week: Understanding Phishing and Social Engineering
As Cybersecurity Awareness Month concludes, we’re sharing bonus content that highlights phishing and social engineering – two prevalent tactics used by attackers to manipulate individuals into disclosing sensitive information or engaging with malicious links. Stay informed and vigilant.
What Is Phishing?
Phishing is a type of cyberattack where attackers impersonate trusted entities: such as university officials, IT support, or even fellow researchers; just to trick you into revealing sensitive information or clicking malicious links.
Common signs of phishing emails:
What Is Social Engineering?
Social engineering goes beyond email. It also involves manipulating people into giving up confidential information via phone calls, text messages, or in-person tactics. Examples:
How You Can Stay Safe
Additional Resources and Tips
Facts and Figures
Spread the Word
Cybersecurity is a shared responsibility. Please share this message with your colleagues and students. Together, we can build a safer academic environment.
Our emails and supporting information are available from the
National Cyber Security Awareness Month (NCSAM) page on the CUNY web site. We also provide a growing security resources list on the
CUNY Information Security pages. You may also want to visit the
OUCH! website to read recent security articles or subscribe to the world’s leading, free security awareness newsletter designed for technology users.
For additional Security Awareness resources go to: Awareness
To report suspicious emails or spam use the yellow banner address that accompanies all emails originating outside of CUNY at
If you have any questions about any of this information, please contact Kazi Islam kislam@PROTECTED our Information Security Manager
YorkIT
Greg Vega
Interim AVP/CIO
York College Information Technology
718-262-5231