RIT Information Security
Stay ahead of digital threats with our expert tips & safeguarding RIT’s information resources.
The Information Security Office provides strategy definition, risk assessment, standards development, communication & training, and investigation of threats & incidents.
07/28/2026
🔍 Great catches in the comments — this one had 5 red flags, and it’s a type of attack called “Quishing” — QR code phishing.
Here’s the full breakdown of what gave it away:
🚩 1. Sent from [email protected] — RIT IT will NEVER contact you from a Gmail address. All legitimate RIT emails come from .edu only. ❌
🚩 2. Typo in the sender name — “Cantact Support” instead of “Contact Support.” Spelling errors are a classic sign of a hastily crafted phishing attempt. ✍️
🚩 3. Sent to undisclosed recipients — RIT will always address you personally and email you directly. Mass BCC campaigns to hidden recipients are a huge red flag. 👥
🚩 4. QR code instead of a link — Attackers use QR codes because email security tools cannot scan where they lead. Never scan a QR code from an unexpected email. 📵
🚩 5. Vague urgency with no specifics — “Recent security activities” — what activities? Legitimate IT alerts always include specific details, ticket numbers, or direct contact info. 🤔
📧 If you receive something like this, do NOT scan the QR code. Report it immediately to [email protected]
Next week: another scenario. Stay sharp. 👁️
07/27/2026
📲 You get an email asking you to scan a QR code to update your Two-Factor Authentication.
It has the RIT name. It sounds urgent. It even mentions IT Services. ⚠️
But before you point your camera at that QR code — take a close look at this email. 👀
🚩 How many red flags can you spot? Drop your answers in the comments below ⬇️
🕐 The full breakdown posts in 24 hours.
⚠️
07/20/2026
✅ Great catches in the comments — this one had 6 red flags, and it was 100% real.
Here’s the full breakdown of what gave it away 🔍
🚩 1. Sent from a student email — RIT IT never contacts you from a student account.
🚩 2. Mass-sent to 191+ recipients — legitimate university emails are never bulk-blasted like this.
🚩 3. “24-hour deactivation” threat — pure pressure tactic to stop you from thinking before clicking. ⏰
🚩 4. The linked form asked for your password, Student ID, date of birth, and BankMobile credentials — RIT will never collect this via a Google Form. 🔐
🚩 5. “Send-only, unmonitored account” — why would an urgent official notice come from an account no one reads? 🤔
🚩 6. Signed by two different offices — Financial Services AND Public Relations. No real university email does this. ❌
📧 If you received something like this, report it immediately to [email protected].
InfoSec StudentSafety
07/16/2026
🎣 This email actually landed in some RIT student inboxes recently.
It looks official. It has the RIT logo. It mentions your financial aid. It threatens account deactivation in 24 hours. ⏳
But something is seriously wrong with it. 🚨
👀 Take a close look — how many red flags can you find? Drop your answers in the comments below. ⬇️
🕐 The full breakdown posts in 24 hours.
07/09/2026
✅ Great catches in the comments — you spotted the key red flags.
🚨 Here is a breakdown of the 4 signs that give this phishing email away:
1️⃣ 🌐 Fake sender domain — the email came from rit-edu.helpdesk.net, not rit.edu. RIT will never contact you from a third-party domain.
2️⃣ ⏳ Artificial urgency — “48-hour processing delay” is a classic pressure tactic designed to stop you from thinking clearly before you click.
3️⃣ 🖱️ Suspicious call to action — no legitimate financial aid office will ask you to “verify banking details” by clicking a link in an email.
4️⃣ 📧 Reply mismatch — the email says “do not reply” but provides a different contact address. Both are fraudulent.
🛡️ If you ever receive an email like this, do not click any links. Report it directly to [email protected].
👀 Next week: a different scenario. Stay sharp.
RIT StudentSafety
07/08/2026
🎣 This email landed in student inboxes recently — and it looks convincing at first glance.
💸 A “financial aid disbursement” of $3,840.
⏰ An urgent deadline.
🔵 A big blue button.
🔍 Before you click anything, take a close look. How many red flags can you find in this email?
💬 Drop your answer in the comments. We’ll post the full breakdown in 24 hours.
⚠️ Phishing attacks on universities spike at the start of every semester — when students are expecting tuition updates, aid disbursements, and enrollment confirmations. That timing is not a coincidence.
12/17/2025
A newly revealed flaw in WhatsApp and Signal allows attackers to silently track users in real time and even drain their phone batteries and data. Security researchers warn that by exploiting delivery receipts and measuring round‑trip times, adversaries can monitor over 3 billion users worldwide simply by knowing their phone number, uncovering details such as when someone is home, asleep, or actively online—all without triggering notifications. The vulnerability, dubbed Silent Whisper, highlights a fundamental weakness in the messaging protocols and raises urgent concerns about privacy and resilience against stealth surveillance.
Read more here;
Over 3 billion WhatsApp and Signal users can be tracked in real time by anyone A publicly released tool can exploit a vulnerability in WhatsApp and Signal’s delivery receipts to secretly track the real-time activity of over three billion users, while also draining battery and data.
Make sure to always check those emails for spelling errors and grammar mistakes! Theyre a common sign that the email is spam or phishing you!
Here are a few ways you can protect yourself:
Check the email address carefully: Phishers often use addresses that look similar to legitimate ones (e.g., [email protected] instead of [email protected]).
Hover over links before clicking to see the actual URL destination. If it looks strange or doesn’t match the sender’s domain, don’t click.
Be cautious with urgent messages claiming your account will be locked or that you must act immediately. Phishers rely on panic to trick you.
12/10/2025
🌐 Cybersecurity Students Making a Difference!
RIT students are stepping up to help local nonprofits and community organizations stay safe online, offering pro bono cybersecurity services that protect sensitive data and strengthen digital defenses. 💻🔒
This initiative not only secures vital community resources but also gives students real-world experience in tackling today’s cyber threats.
Read more about how they’re creating impact:
How pro bono services from cybersecurity students are helping secure community organizations With RIT’s Cybersecurity Clinic, students are gaining real-world pentesting and vulnerability assessment experience, while also helping the community.
Phishy pulls a UNO reverse on the tiger fish 🐟➡️🐟… tried to eat me, got eaten instead!
Click here to claim your Sponsored Listing.
Contact the business
Telephone
Address
1 Lomb Memorial Drive
Rochester, NY
14623