Members of the º£½Ç½ûÇø community continue to be impacted heavily by a phishing scam that asks º£½Ç½ûÇø community members to fill out a Google form with their º£½Ç½ûÇø account information. These types of attacks can result in personal and financial information being compromised.
University of Kentucky Information Technology Services (º£½Ç½ûÇø ITS) cyber security experts say it’s crucial to spot and report these types of phishing emails because falling victim to them may not only compromise your account, but it may harm the university community.
“These URLs are not malicious in nature — they're just Google Forms," said ITS Director of Cybersecurity John Lewis. "However, if users input sensitive information such as passwords or MFA codes into these forms, attackers can easily take over the account."
º£½Ç½ûÇø ITS wants the university community to be on the lookout for these types of phishing scams. Here are some important tips to remember.
- º£½Ç½ûÇø ITS will never reach out to you to ask for a password. Never share your password unless you have called IT technical support directly.
- Do not approve multi-factor authentication pushes if you have not requested one. This type of cyber threat is called MFA fatigue. Cybercriminals likely have your password and only need you to approve an MFA code and often request them multiple times until you approve.
- Always check the sender’s email address. º£½Ç½ûÇø ITS emails end with a .uky.edu email address. Recent threat actors have used non-º£½Ç½ûÇø Gmail and other addresses to threaten º£½Ç½ûÇø students, faculty, and staff with account deactivations.
- Never fill out forms sent via email regarding your º£½Ç½ûÇø account status. Any changes to your º£½Ç½ûÇø account must be made through the Account Manager at ukam.uky.edu, not a form. You will then be notified of any changes via your º£½Ç½ûÇø email. Report suspicious emails. This allows º£½Ç½ûÇø ITS to handle phishing and social engineering attempts. Step-by-step instructions can be found in
- Be cautious about giving away personal information in a text or phone call. The only contacts that should ever ask for your º£½Ç½ûÇø account information would be ITS Customer Services at 859-218-HELP (4357) or º£½Ç½ûÇø HealthCare IT at 859-323-8586. Do not give any account information over the phone unless you have called them directly. º£½Ç½ûÇø ITS cannot help with cyber-attacks that happen over personal devices.
More information can be found .