University of Wisconsin–Madison
Keyboard with money being taken away by a fishing hook

8/16 Phishing Alert! Subject: “Benefits”

The UW–Madison Office of Cybersecurity is aware of an active phishing campaign on campus in which the attacker offers to “provide $2300 in assistance for qualifying employees who are experiencing financial hardship.” See the screenshot:

Screenshot of phishing message

NOTE: The most recently reported phishing email like this example was sent August 16, but such attacks can occur at any time. Please be on the lookout.

How can I identify this phishing attempt?

  • The first paragraph contains a spelling/grammatical error: “support all Student & employees to get through these hard times.”
  • The hyperlinked “WSC COVID-19 Benefits” text contains a spelling error (WSC instead of WISC) and links to a non-UW URL.

Always scroll over each hyperlink

The most important habit to practice in order to protect yourself from phishing attempts is to always scroll over each hyperlink, whether words or URL, to see what web address the link actually goes to. When you scroll over a hyperlink, its destination URL displays as a tool tip.

What should I do if I receive this phishing attempt?

Use the option in Outlook to “Report a Phish” and it will be deleted from your inbox. For more details, see Office 365 – Submit a message as spam/phishing (Source: KB 45051).

What should I do if I accidentally clicked one of the fake portal links?

Immediately change your NetID password by following the instructions in NetID: Changing a Password (Source: KB 20589).

Also the Office of Cybersecurity recommends the following if you submitted any information after clicking:

  • Report stolen credit card information to the appropriate Banking institution.
  • Report the identity theft to your local PD and to the Federal Trade Commission’s website.

How can I learn how to recognize other phishing attempts?

Go to Learn how to recognize and report phishing (Source:

Stay updated on phishing attempts by visiting our Scam alerts page (Source:

If you are ever unsure whether an email message is legitimate, do not respond to it. Contact the DoIT Help Desk (608.264.4357) for advice. The UW–Madison Office of Cybersecurity will then block the criminal element from sending further emails and gather evidence for eventual prosecution of the crime.