Helendale School District Technology Services

Mail Threat Response

Phishing that reaches a district mailbox is found and removed from every inbox it touched, usually within minutes. Here is what is circulating, how to report one, and how the district is doing.

Sweep

Helios Sweep

4
Campaigns, last 30 days
reports, last 12 weeks
4
Copies removed
removals, last 12 weeks
4
Mailboxes protected
4 had already been opened
822
Phishing sites checked this week
feed matches, last 12 weeks
Staff

Got a suspicious email?

Sign in with your district Google account, tap the message in your own inbox, and it is pulled out of everyone else's while the technology department checks it. One tap protects the whole district.

Staff sign in with Google Only your name and email address are requested from Google. Nothing in your mailbox is read until you choose a message.
Everyone

What is circulating now

  • “NEW MAIL!!!! Re: Action Needed: Review Finish Schedule”sent as deltaconstructionflorida.com · 1 mailbox · under review
  • “Re: Thank You for Your Order 0AF0HJANZWPKZEIN”sent as Paige Collins · 1 mailbox · confirmed
  • “Patrice Mock sent you a document”sent as rimsd.k12.ca.us · 1 mailbox · confirmed
See all current threats No sign in. Quoted so you recognise them; no links to any of it.

 Watch out for

From the OpenPhish and Phishing.Database feeds, which the district checks against its own mail every day. Last check Sep 21, 2026 8:05 am.

144New phishing sites today
822This week
0Reached the district

Brands being impersonated this week

Amazon 41Netflix 20Instagram 11Facebook 9Steam 8Roblox 5Apple 5AT&T 3

A message claiming to be from one of these that asks you to sign in, confirm an account, or open a document deserves a second look at the sender's real address.

Where phishing sites live this week

.com addresses233
.cfd addresses42
.xyz addresses21
.info addresses17
.shop addresses17
.net addresses15

District mail comes from helendalesd.com. A familiar name on an unfamiliar ending is the tell.

 Aimed at us

Names, not links. Domains pretending to be the district, and phishing sites whose links actually arrived in district mailboxes.

Reached district mail and removed

None of this week's published phishing sites have appeared in district mail.

Watch this live on the wall board

Know the signs

How to spot a phishing email in Gmail

The district runs Google Workspace for Education, so every staff mailbox is Gmail. These six checks take ten seconds and catch nearly everything.

Look at the address, not the name

In Gmail, tap the sender's name to reveal the real address. "HSD Payroll" on a gmail.com or an odd domain is the whole story. District mail comes from helendalesd.com.

Hover before you click

On a computer, rest the pointer on a link and read the address in the corner of the window. On a phone, press and hold the link to preview it. If it is not where the text says, do not go.

Never sign in from an email link

Google, Aeries, and every district system will still be there when you open them yourself. A sign-in page that arrives by email is the single most common trick.

Urgency is the tell

"Today", "immediately", "your account will be closed", "the superintendent needs this now". Real requests survive a phone call to check.

Unexpected attachments and shares

A document you were not expecting, especially a "shared file" notification or an invoice, deserves a question to the sender by another route before it is opened.

Trust Gmail's own warning

Gmail shows a yellow or red banner on mail it finds suspicious. Believe it. If a message has one, report it rather than reading further.

What happens next

When you report a message

1You tap the message

Sign in with your district Google account and choose the message from your own inbox. Nothing else in your mailbox is read.

2Every mailbox is searched

The same message is found in every district mailbox it reached, usually within a minute or two.

3Every copy is removed

It goes to Trash for everyone, immediately. If the technology department finds it was legitimate, every copy is put back exactly as it was.

4You hear back

When the department confirms or releases it, you get a short note saying what it was and what happened.

Questions

Frequently asked

What is phishing, exactly?

An email, text, or chat message that pretends to be from someone you trust, a colleague, a vendor, Google, the district, in order to get you to click a link, open a file, or enter a password. The goal is almost always your sign-in, because a district account opens the door to everything else.

Will I get in trouble for reporting something that turns out to be fine?

No. Never. A careful report is exactly what we want. If a reported message turns out to be legitimate, the department releases it and every copy goes back to every inbox unchanged. Reporting is the district's earliest warning, and the people who report most are the people we thank.

I clicked the link. What do I do now?

Tell the technology department straight away, by phone or ticket, and say what you did: clicked, opened, or entered a password. If you entered your password, change it immediately at accounts.google.com and sign out of other sessions there. There is no penalty for a click; there is real risk in silence.

A message disappeared from my inbox. Why?

Someone reported it and it was removed from every mailbox it reached, including yours, while it is checked. If it was legitimate it will reappear exactly as it was. If it stays gone, it was phishing, and the current threats page will show it.

What is the difference between spam and phishing?

Spam is unwanted advertising; it wastes your time. Phishing wants something from you: a password, a payment, a file opened. Report phishing. Plain spam can simply be marked as spam in Gmail, which teaches Google's filter.

How do I see the real sender in Gmail?

On a computer, open the message and click the small arrow under the sender's name to see "from", "reply-to", and "mailed-by". On a phone, tap the sender's name. If "reply-to" is a different address from "from", be suspicious.

What about Google Drive and Docs share notifications?

They are a favourite disguise, because they look exactly like the real thing. A real share comes from drive-shares-noreply@google.com and opens in your own Drive without asking you to sign in again. If a "shared document" asks for your Google password, it is phishing.

Can I just use Gmail's Report phishing button?

Yes. Reports made with Gmail's own Report phishing button reach the district's system as well, and are handled the same way. The portal on this page is faster and lets you see the result, but either works.

Does the district read my email?

No. When you report a message, only that message is examined, and only to find and remove the same message from other mailboxes. The department sees the sender, subject, and how many mailboxes it reached, and keeps one copy as evidence. Nothing else in your mailbox is read.

Why do scammers target a small school district?

Because a district account is trusted by parents, vendors, and other districts, and because payroll and vendor payments run on email. Small districts are targeted precisely because they have fewer people watching. This page exists so that everyone is watching.

Some of these are practice, aren't they?

Yes. The district runs Red Herring phishing simulations: realistic practice messages sent to staff. If you report one, nothing is removed, and you hear back that it was a test and you passed. Reporting a simulation is exactly what we hope you will do; it is the same reflex that stops a real one. About the awareness program.

Where can I learn more?

The current threats page shows what is circulating right now, quoted so you recognise it. The staff awareness email, when the department has it switched on, arrives on a schedule with the same information. The district's awareness program, Red Herring, has its own training material at redherring.sdcoe.net. For anything else, open a ticket with the technology department.

Para padres y familias

English

Los estafadores imitan a las escuelas porque las familias confían en ellas. El Distrito Escolar de Helendale nunca le pedirá pagar una cuota, confirmar una contraseña ni actualizar datos de pago a través de un enlace en un correo o un mensaje de texto. Si un mensaje que dice ser del distrito parece extraño, no haga clic y consulte con la oficina de la escuela.

¿Cómo sé si un mensaje realmente viene de la escuela?

Los mensajes verdaderos del distrito llegan desde el dominio propio del distrito y nunca le piden pagar, confirmar una contraseña ni actualizar datos de pago a través de un enlace. Si tiene dudas, cierre el mensaje y llame a la oficina de la escuela; una solicitud real resiste una llamada telefónica.

Recibí un mensaje de texto sobre un saldo de almuerzo, una cuota o un paquete. ¿Es real?

El distrito no cobra pagos por mensaje de texto y no envía enlaces para pagar. Borre el mensaje. Si quiere revisar un saldo, abra el portal para padres usted mismo en lugar de seguir un enlace.

El mensaje dice que la cuenta de mi hijo se cerrará si no actúo ahora. ¿Qué hago?

Nada, por ahora. La urgencia es el truco más viejo del phishing. Llame a la oficina de la escuela durante el día y pregunte. Ningún sistema del distrito cierra una cuenta porque un padre no hizo clic en un enlace.

Más preguntas y las amenazas actuales

A local account for this application only. Not your Google password; never sent to Google.