Know Your Opponent

Emails Can Be Spoofed

Email spoofing is the creation of email messages with a forged sender address. Often these phishing emails will come from names you know, or are familiar with and have an urgent request. Some may demand that you "update your account information" or "login to confirm ownership of your account".  

Attackers may also set up web sites under their control that look and feel like legitimate web sites. If you enter your credentials into these illegitimate websites, you are sending your username and password directly to the attackers. Stop and look at the email address before you reply and don't click any unexpected links or attachments.
 

To keep you and your information safe:

Dodge their attacksand counterby reporting it:

Using the bMail web interface:

  1. Open the message
  2. To the right of 'Reply' arrow, select 'More' (typically denoted with three vertical dots)
  3. Then 'Report phishing'

If you are unable to log into bMail forward the message to phishing@berkeley.edu

graphics courtesy of Anne Tambe