
Cyber criminals rely on urgency, fear, authority, curiosity, and distraction to pressure people into acting quickly. Phishing attacks are becoming increasingly sophisticated and may reference real University systems, departments, projects, or people. Some may even come from compromised accounts.
Knowing how to respond when something feels off can help protect both you and the broader Waterloo community.
Learn how to identify phishing and avoid becoming a victim. Visit Defend Against Phishing at Waterloo.
The PAUSE Framework
When you receive an unexpected email, message, attachment, login request, or financial request, use the PAUSE framework before acting.
P - Pause
Take a breath and interrupt the urge to react immediately. Create space between receiving messages and responding. Avoid making important decisions while multitasking, rushing between meetings, or responding from your phone. Slow down, focus on the request, and assess it before taking action.
A - Awareness
Pay attention to how the message makes you feel.Does it create:
- Urgency?
- Fear?
- Excitement?
- Curiosity?
- Pressure?
Strong emotional reactions can be warning signs.
U - Unpack the Message
Look more closely at what is being asked.
- Does the sender’s email address match who they claim to be?
- Are you being asked to click a link, approve a login, transfer funds, purchase gift cards, or share information?
- Does the request make sense in the context of your role?
- Is this consistent with how the University normally operates?
S - Select the Next Step
Choose your response on your terms.
- Contact the sender independently by verifying through a trusted channel, like in-person or Microsoft Teams
- Navigate directly to a known website instead of clicking a link.
- Seek a second opinion.
- Decide not to proceed.
The attacker does not get to decide your next step.
E - Escalate
Report suspicious emails, scams, fraud, or account compromises to the Security Operations Centre (SOC) or appropriate organization immediately. Early reporting helps protect both you and others who may be affected.
If you think you've been hooked
If you believe you may have interacted with a phishing message, scam, fake website, suspicious attachment, or fraudulent request, act quickly. Early action can help reduce the impact and protect both you and the Waterloo community.
1. Stop and Report
- Do not continue interacting with it.
- Do not reply to the sender.
- Do not provide additional information.
- Report it to the SOC by submitting the suspicious email as an attachment . This preserves the original message and technical details for investigation. Avoid forwarding suspicious emails to others, as this may spread malicious content or create unnecessary alarm.
2. Protect your accounts
If you entered credentials or approved an unexpected authentication request:
- Change your WatIAM password immediately.
- Change any other accounts using the same password.
- Review 2FA settings and registered devices.
- Watch for unusual account activity or unexpected Duo prompts.
Remember: Never share your password or Duo verification codes with anyone.
3. Protect your device
If you downloaded software, opened a suspicious attachment, or believe your device may be compromised:
- Stop using the software or file.
- Disconnect from the internet if instructed by IT support.
- Report the incident to the SOC.
- Follow guidance from your local IT support team or the SOC.
Additional remediation steps may be necessary, including:
- Removing malicious software.
- Deleting malicious files.
- Resetting browser settings.
- Rebuilding the operating system
4. Protect your finances and identity
If personal, financial, or government-issued information was shared:
- Contact your financial institution immediately.
- Contact the affected vendor or service provider.
- Monitor accounts and credit reports for suspicious activity.
- Review identity theft recovery guidance.
Report fraud to the appropriate authorities.
No shame. Just report.
Modern scams are intentionally designed to look legitimate. Attackers use compromised accounts, trusted brands, social engineering techniques, and increasingly AI-generated content to make fraudulent messages appear authentic.
If you:
- Clicked the link,
- Opened the attachment,
- Entered your credentials,
- Approved the Duo prompt,
- Sent information,
- Sent money,
report it anyway.
The sooner an incident is reported, the sooner it can be investigated, contained, and used to protect others.
Reporting an incident is not admitting failure. It is one of the most effective ways you can help protect yourself and the University community.
Pause. Assess. Report.
When in doubt, don't keep it to yourself. Your report may help protect someone else from becoming the next victim.