Phishing has recently become one of the most popular methods of data theft, utilising elements of social engineering. It is a type of cyberattack in which an attacker attempts to deceive users by impersonating trusted institutions or individuals to obtain confidential information, such as passwords, credit card numbers or personal data. This attack often involves sending fraudulent emails that appear to come from well-known companies, banks or social media platforms. The recipient is encouraged to click on links or provide information, which can lead to data theft or other adverse consequences.
The simplest and most easily recognisable forms of fraudulent messages are prepared en masse, sometimes simultaneously for recipients in multiple countries. As a result, the content of such messages often contains linguistic errors typical of machine translation or individuals who are not fluent in the language.
However, it is important to remember that in professionally crafted attacks, the message may be written by a native Polish speaker; therefore, even grammatically correct content does not guarantee that the message is safe.
Phishing messages are most often sent from free email accounts and other users' accounts that have been compromised by an attacker. It is worth paying attention to the "From:" field, which identifies the sender of the message. If the domain (the part of the address located after the '@' symbol) is not the AGH University domain (agh.edu.pl) or its subdomain (an address that has additional segments on its left side, such as cri.agh.edu.pl, chor.agh.edu.pl, open.agh.edu.pl and similar), you should approach such a message with particular caution. Similarly, all messages from free email accounts (such as gmail.com, yahoo.com, etc.), accounts from other countries (especially non-European ones), or the complete absence of a sender's address should be treated as suspicious.
When checking the domain, inspect it carefully. Well-prepared fraudsters typically use addresses with hard-to-detect typos. For instance, the letter 'l' is sometimes replaced by the number '1', and an uppercase or lowercase 'o' by the number '0'.
Please remember that individual segments in a domain address are always separated by dots, and not by other characters, such as hyphens or underscores. Therefore, a sample address like informatyka.agh-edu.pl is not owned by AGH University (note the hyphen in the middle).
Even if the address contains the agh.edu.pl segment, but it is not located on the far right side of the address, such a domain does not belong to AGH University, and its use is likely associated with a fraud attempt.
agh.edu.pl-online.com
agh.edu.pl.24.eu
aghedupl.co.zw
agh-edu.pl
agh.cri.edu.pl
agh.odu.pl
agh.com.pl
Phishing attackers aim to instil a sense of anxiety in the user and a fear that something unpleasant is about to happen. Therefore, a frequently used motif is a warning about an unpaid service, an email account being blocked, or a violation of the law or good practice. The attacker wants the user to act as quickly as possible, without thinking the situation through.
Such a strategy has even coined a specific term: FUD (Fear, Uncertainty, Doubt), which refers to techniques commonly used in propaganda and disinformation.
Please remember that administrators will always inform you about upcoming actions (e.g., email server downtime, account deletion due to a lack of confirmation for the following year, etc.) well in advance, and their goal is never to intimidate users.
Always give yourself time to think and avoid reacting instinctively.
Please remember that administrators will never ask you to provide your account credentials (login, password, one-time codes) or other sensitive data (PESEL number, payment card number, etc.) via email.
Pay particular attention to messages containing links to external websites that require you to log in. Usually, visiting a website via a link does not pose any risk, provided you do not enter any data on the site or perform any additional actions (e.g., downloading files).
If you do follow a link, it is essential to verify the website's address. The domain should belong to AGH University (the domain is the part of the address between https:// and the next forward slash /). The rules for determining whether a domain belongs to AGH University are the same as in point 2.
Keep in mind that the link displayed in the message body may not represent the actual destination address. Below is an example of a link that has been masked with different text. To reveal the true link, you need to hover your mouse over it. A bar displaying the actual address will then appear in the bottom-left corner of the screen (in Microsoft Outlook, a tooltip with the address will also appear).
If the recipient address of the message is not yours, or if it is missing altogether, the message was most likely sent using an automated solution rather than by a human. This could also be the result of a misconfiguration; however, it is a fairly common occurrence in messages involving fraud or data theft.
Please remember that the message might also have been sent to multiple recipients using the blind carbon copy (BCC) mechanism. In such a case, you will not see the list of recipients, and the message itself may be legitimate and not a fraud attempt.
Fraudsters want their recipients to act instinctively and without thinking too much about their actions. This is why many attacks include a message stating that you must take some action within the next 24 hours, or that something – invariably negative – has already occurred. If you are unsure how to react, do not react at all. It is better to ignore a suspicious message and take action later (if necessary at all) than to fall victim to an attack.
Much of the information regarding planned maintenance work, pending regulations to be accepted, or payment delays (and the threatening consequences) can be easily verified.
Announcements from AGH University administrators are published on the IT Solutions Centre website (https://www.cri.agh.edu.pl/). Even if you cannot find the information you are looking for, you can contact the IT Helpdesk (https://pomoc-it.agh.edu.pl/).
Please remember not to use the contact information provided in a suspicious message. The attacker may have intentionally included fake links or phone numbers operated by a fraudster. You can see how sophisticated such an attack can be here (https://www.youtube.com/watch?v=SbCcmLqmQSs).
Even if the message contains details that might suggest it is authentic (for example, it is signed by someone you know personally or who you know works at AGH University, and their department and job title match), this does not guarantee its authenticity. Much of this information can be found on the internet and obtained by anyone who wishes to do so.
If the sender of a suspicious message is a fraudster, they will attempt to convince you that the message is authentic and that you should comply with their requests as quickly as possible. To verify whether the message is genuine, follow the recommendations in the previous section.
Email-based attacks frequently utilise malicious attachments, which can be executable files or files containing a short script program, known as a macro. Even seemingly innocent files, such as Word, Excel, or PDF documents, can contain malicious code.
Regularly update your computer's software and do not open attachments from unexpected messages that you cannot verify according to the rules outlined above.
For matters related to cyberattacks and other IT security issues, you can contact us at security@agh.edu.pl.
To facilitate our analysis, please save the suspicious message as an .eml file (using the "Save as" option available in most email clients) and send it to us as an attachment.

Wersja 1.
Version 1. In the upper right corner (above the message) More => Save as
Right click on a message => Save as…
In the middle, in the upper right corner of the message window, click the "message with note" sign => "Forward as attachment"
Click on the gear wheel in the top menu => Download (.eml)