With an increase in scams popping up in campus emails, Student Affairs and Information Technology partnered to launch an anti-phishing campaign.
Phishing refers to attempts to steal sensitive information, such as passwords and bank information.
Tim Roach, program director of IT, said UCA has dealt with “roughly 15-20 reported phishing attempts” since Jan. 1. In fall 2024, over 100 phishing attempts were reported to IT.
Alexandria Smith-Todd, assistant director of Student Affairs, took the lead in creating the campaign.
“Using information provided by the IT division, The Student Affairs communication team with the help of our amazing student staff has created a plethora of digital content to educate on phishing,” Smith-Todd said.
Ryan Webb, a junior political science major, joined the anti-phishing campaign after his friend asked him to.
“My role is making sure students don’t fall for the same scam I fell for a year or so ago,” Webb said.
Webb said he received an email through his UCA cub account.
“I had an idea that it was a scam because of the spelling and grammatical errors in the email. I didn’t respond for a while but a friend of mine had gotten the same email and told me I should go for it — I really trusted this friend — and I did,” Webb said. “My chat with the scammer went from email to text and I ended up giving this jerk a lot of my information via text. The scammer sent me a pic of a fake check to endorse to buy the stuff he told me I would need to do my work.
“I showed my mom and she told me that the check was fake. My mom worked in banking for 30 years or so, so she’s seen a lot of fake checks. I then blocked the number. I told the professor the guy was posing, but didn’t get a response from him. It was ridiculous. I’m even embarrassed to share that I got duped like that against my better judgment,” he said.
Webb said the anti-phishing campaign is important because it helps the campus community stay safe.
“It ensures the digital and possible physical safety of UCA students,” he said. “The scam I fell for consisted of me giving very personal information to this scammer such as my social security number and address. No one should ever be duped like I was.”
Roach said it is important to raise awareness about phishing attempts “because the ultimate goal of phishing is to steal personal or university data for nefarious reasons, the more that our campus community knows about current phishing activity, the basics of how phishing works and what it looks like, and how best to defend themselves — including what information they should never provide through email — the better our chances are to protect individuals and the university from data theft.
“Impacts of phishing are not just limited to data being stolen, from there it may become a financial and reputational impact at both the individual and university level,” he said.
Roach said the IT department works to identify phishing attempts and trends.
“The UCA IT Division has multiple teams and individuals that provide not only their expertise in the creation or guidance of the anti-phishing campaign, but they also play a critical role in the identification of new phishing trends and threats as they begin to make their way through the university,” Roach said. “UCA IT also provides information for the campaign to ensure our university is aware of information that we never ask you to provide via email such as password or account information. The bad actors that would initiate phishing campaigns, no matter their intent, will use analytics to determine weaknesses in an organization and exploit them and then modify their approach to counteract the defenses we in IT deploy. The phishing landscape will be one that is ever-changing.”
Smith-Todd provided a list of tips for avoiding phishing attempts.
-
Don’t trust emails from suspicious addresses like [email protected]; always verify the sender.
-
Don’t fall for urgent or panic-inducing messages, such as “Act now!” “Urgent Action” or “Your account will be suspended!”
-
Don’t ignore impersonal greetings like “Dear User” or “Valued Customer”; legitimate emails use your name.
-
Don’t click on strange attachments or links without checking their source — hover over links to see where they lead.
-
Don’t share sensitive information like passwords, Social Security numbers or payment details through email; no real company will ask for this.
Webb said not to trust emails that may be “too good to be true.”
“If someone is offering you a significant amount of money for little to no work, you’re being tricked. No one is going to pay you good money if you don’t possess any skills,” he said. “Also, if there is no interview and you are hired on the spot, it’s not legit. Chances are employers are not going to like you like that or take that kind of risk.”
More information about the anti-phishing campaign can be found on Instagram @uca_studentaffairs.



