What is phishing, exactly?
An email, text, or chat message that pretends to be from someone you trust, a colleague, a vendor, Google, the district, in order to get you to click a link, open a file, or enter a password. The goal is almost always your sign-in, because a district account opens the door to everything else.
Will I get in trouble for reporting something that turns out to be fine?
No. Never. A careful report is exactly what we want. If a reported message turns out to be legitimate, the department releases it and every copy goes back to every inbox unchanged. Reporting is the district's earliest warning, and the people who report most are the people we thank.
I clicked the link. What do I do now?
Tell the technology department straight away, by phone or ticket, and say what you did: clicked, opened, or entered a password. If you entered your password, change it immediately at accounts.google.com and sign out of other sessions there. There is no penalty for a click; there is real risk in silence.
A message disappeared from my inbox. Why?
Someone reported it and it was removed from every mailbox it reached, including yours, while it is checked. If it was legitimate it will reappear exactly as it was. If it stays gone, it was phishing, and the current threats page will show it.
What is the difference between spam and phishing?
Spam is unwanted advertising; it wastes your time. Phishing wants something from you: a password, a payment, a file opened. Report phishing. Plain spam can simply be marked as spam in Gmail, which teaches Google's filter.
How do I see the real sender in Gmail?
On a computer, open the message and click the small arrow under the sender's name to see "from", "reply-to", and "mailed-by". On a phone, tap the sender's name. If "reply-to" is a different address from "from", be suspicious.
What about Google Drive and Docs share notifications?
They are a favourite disguise, because they look exactly like the real thing. A real share comes from drive-shares-noreply@google.com and opens in your own Drive without asking you to sign in again. If a "shared document" asks for your Google password, it is phishing.
Can I just use Gmail's Report phishing button?
Yes. Reports made with Gmail's own Report phishing button reach the district's system as well, and are handled the same way. The portal on this page is faster and lets you see the result, but either works.
Does the district read my email?
No. When you report a message, only that message is examined, and only to find and remove the same message from other mailboxes. The department sees the sender, subject, and how many mailboxes it reached, and keeps one copy as evidence. Nothing else in your mailbox is read.
Why do scammers target a small school district?
Because a district account is trusted by parents, vendors, and other districts, and because payroll and vendor payments run on email. Small districts are targeted precisely because they have fewer people watching. This page exists so that everyone is watching.
Some of these are practice, aren't they?
Yes. The district runs Red Herring phishing simulations: realistic practice messages sent to staff. If you report one, nothing is removed, and you hear back that it was a test and you passed. Reporting a simulation is exactly what we hope you will do; it is the same reflex that stops a real one. About the awareness program.
Where can I learn more?
The current threats page shows what is circulating right now, quoted so you recognise it. The staff awareness email, when the department has it switched on, arrives on a schedule with the same information. The district's awareness program, Red Herring, has its own training material at redherring.sdcoe.net. For anything else, open a ticket with the technology department.