Skip to main content

Beware of Phishing Scams Impersonating Ohio State

hacker typing on laptop

Ohio State is aware of a phishing scam targeting students with emails that claim to be related to attorney-client privilege or account verification. Phishing scams usually ramp up when students return for fall classes. Like many phishing messages, the current scam attempts to create urgency and directs recipients to "verify" or log in to their Microsoft 365 account through an external link.

Any messages you receive like this one are fraudulent. Ohio State will never ask you to provide your password through email, and you should be cautious of any message that pressures you to click a link and sign in to keep your account active, prevent suspension or verify your information.

How to spot the scam

Signs that an email may be fraudulent include:

  • Unexpected requests to verify your account or password
  • Messages that create urgency or threaten account disruption
  • Links that direct you to unfamiliar websites
  • Requests for personal information or login credentials
  • Spelling, grammar or formatting issues
     

What to do if you receive the message

If you receive a suspicious email:

  1. Do not click any links or open attachments.
  2. Do not enter your Ohio State username or password.
  3. Use the "Report Suspicious" button in Outlook to report the message.
  4. Delete the email after reporting it.

If you entered your Ohio State credentials on a suspicious website, get assistance by contacting the IT Service Desk online, by phone at 614-688-4357 (HELP) or via email at ServiceDesk@osu.edu.
 

Stay vigilant

Cybercriminals frequently impersonate trusted organizations, including universities, to steal passwords and sensitive information. Taking a moment to verify unexpected requests can help protect your personal information and Ohio State systems.

Learn more about identifying and reporting phishing attempts at Ohio State's cybersecurity awareness resources.