Skip to main content

Defend Your Inbox: The New Way to Report Phishing

July 16th, 2026

The Office of Information Security has rolled out to new phishing reporting tool and is providing tips for spotting modern phishing. With a number of sophisticated phishing attempts occuring at CWRU, it's important for all of us to stay alert and be aware of the signs and dangers of these attacks.

Abnormal Phishing Button

Spotting Phishing Attempts

Before you click any link, download an attachment, or reply, pause and check for these common indicators:

  • Fake Login Pages: Scammers send links to websites designed to look like the real CWRU login screen. Before you type your password, always check the web address to make sure it's the official university site (https://login.case.edu).
  • "External" Warning Tags: Emails from outside the university get an "External" label. If you see this, pause and ask yourself: "Do I know this person, and does it make sense they are emailing me?"
  • Fake Emergencies: Scammers try to panic you into acting immediately. They might claim you need to cancel an unexpected order, fix a shipping issue, or unlock your account. If a message demands urgent action, it is usually a trick. 
  • Faked Names: A scammer can easily change their display name to look like someone at the university. Always check the actual email address hidden behind the name to see who really sent it.
  • Unknown attachments: Never click on attachments you weren't expecting to receive (e.g., random invoices, resumes or zip file). 
  • Password Requests: University Technology will never email you asking for your password. If an email asks for it directly, it is a scam.

For more information about phishing scams, please visit the CWRU Information Security Website.


Quickly Report Phishing Attempts

Once you suspect an email is a phishing attempt or spam, reporting it immediately acts as a shield for the rest of the campus. To make this seamless, the CWRU Office of Information Security has rolled out the Abnormal Report Phish button.

Why use the new reporting button?

  • Instant Automation: Clicking it triggers an immediate automated security review of the email across the CWRU network.
  • Rapid Feedback: The system will send you an automated follow-up email within just a few minutes sharing the results of the analysis.

How to find it:

  • On Gmail Web: Look for the Abnormal Report Phish icon located in your Gmail client's add-on sidebar.
  • On Mobile Gmail App: The add-on bar will appear at the bottom of the active email.
  • Other Email Clients: This feature is not supported on other email clients, so it is recommended to use the Gmail application on whatever device you are using.

Need Assistance?

If you suspect a message is a threat but cannot locate the new sidebar button, or are using an email client outside of Gmail, you can still report it by forwarding the email to phishing@case.edu.