Phishing emails are still one of the most common ways attackers get passwords, recovery codes, and access to school or personal accounts. They do not need to look obviously fake to work. Most of the time, they just need to make you feel like you need to act fast before you stop to think [1].
This guide gives students and educators a way to assess any suspicious message and a clear plan for what to do next.
🚩 Why Phishing Still Works
Phishing emails do not win because the writing is clever. They win because they arrive when you are busy or distracted.
A typical scam message imitates a real notification — something from Google, Microsoft, a courier service, or your school platform. The language creates urgency: account suspension, unusual activity, billing problems, urgent document review.
Students might encounter fake Google, Microsoft, courier, gaming, or bank messages. Educators might receive account-warning emails, shared-document prompts, or requests that appear to come from a colleague or school leader.
In both cases, the goal is usually one of:
- Getting you to enter your password on a fake login page
- Persuading you to approve a sign-in prompt you did not initiate
- Tricking you into downloading malware or sharing a recovery code
🔍 Warning Signs to Check Before You Click
No single warning sign proves a message is fake, but several together should stop you.
Check the sender address carefully
A message can display a familiar name while using a completely different address underneath. Google's Gmail Help advises users to watch for suspicious messages that look real but ask them to share personal information or click a link they were not expecting [1].
Look past the display name. Check the full sender address. If the email claims to be from Google, Microsoft, your school platform, or a bank, the real sending domain matters — and it will not be a free email service.
Watch for urgency before clarity
A lot of phishing works by making you feel behind, exposed, or about to lose access. The language may mention account suspension, unusual activity, billing issues, or urgent document review.
Urgency alone does not prove a scam. Real services sometimes send urgent alerts. But a legitimate security message should still hold together when you inspect it calmly.
Check the link destination
Hover over the link before clicking. On a phone or tablet, use a long press or another safe preview method if your device offers one. If the visible text says one thing but the destination URL says another, treat it as suspicious.
Google's account-recovery guidance is a good reminder here: when account security is involved, going directly to the service in a new tab is safer than following a message link [2].
Never share passwords or MFA codes
Phishing pages often ask for:
- Your password
- Recovery codes
- One-time passwords (OTP)
- Approval of a sign-in request you did not initiate
No legitimate service will email you asking for your password or MFA code. Any message that does is a phishing attempt, regardless of how official it looks.
Watch for unexpected approval requests
Some attacks do not ask for a password — they ask you to approve a sign-in prompt or OAuth access. If you receive a sign-in approval request that you did not initiate, do not approve it. Check your Google account activity directly at myaccount.google.com [3].
🛡️ What to Do If You Receive a Suspicious Message
If you are not sure
⚠️ Do not click, reply, or download anything. Open a new browser tab and navigate directly to the service in question using a known address — go to google.com and sign in from there, rather than from a link in the message.
If you already clicked
Change your password from a clean device immediately. Check your account activity for anything unusual. Revoke any third-party access you do not recognise. If you use the same password elsewhere, change it there too — a password manager makes this manageable [4].
If you entered financial information
Contact your bank or card provider immediately. Monitor your statements for any unusual transactions. Consider placing a credit freeze with a credit reporting agency if you think your details may have been captured.
If you are in a school environment
Report to your IT team or school leadership. If student data may have been involved, the school may have reporting obligations under the Privacy Act 2020. Do not try to manage this alone.
✅ A Quick Decision Framework
- Does the message create urgency? (Pressure to act fast = yellow flag)
- Does the sender address match the brand it claims to be? (Mismatch = red flag)
- Does the link destination match what the message says? (Mismatch = red flag)
- Is the message asking for a password, code, or approval? (Yes = red flag)
- Would this request make sense if you had not just logged in? (No = yellow flag)
🚨 If you have yellow flags, slow down. If you have red flags, do not click.
This article was originally published on nzaisecurity.com. Read the full article.
📚 Sources and references
[1] Google. Gmail Help. How to recognise and report phishing emails. https://support.google.com/mail/answer/8253
[2] Google. Account Help. Secure your account with recovery options. https://support.google.com/accounts/answer/183723
[3] Google. My Account. Check activity and secure your account. https://myaccount.google.com/notifications
[4] NZ Cyber Security Skills Hub. Password managers explained. https://www.ncsc.govt.nz/resources/cyber-security-basics/password-managers/

Top comments (0)