Spam & Phishing

Spam refers to unsolicited, mass-mailed advertising, which is often of dubious nature.

Phishing refers to attempts, often via spam emails, to steal your login details for a particular web platform.

You can find more information on both topics, as well as tips on how to protect yourself, on the BUW’s information security pages and on the website of the Federal Office for Information Security.

You can increase the spam filter’s sensitivity:

  • Check the sender of the email
    • Check the email address by clicking on the sender’s name.
    • Is it an @uni-wuppertal.de email address?
    • Do you recognise the sender?
    • Is the sender using a valid email signature?
    • If you are unsure, contact the sender via another channel, e.g. by telephone.
  • Pay attention to spelling and style
    • Spelling mistakes, missing or incorrect special characters can be a sign of a phishing email.
    • Unusual phrasing may also be a sign of a phishing email.
  • Be wary if pressure is being applied.
    • If pressure is being applied or you are asked to enter personal details, this may also be a sign of a phishing email.
  • Be wary of links.
    • If in doubt, do not click on any links!
    • Check links by hovering your mouse over them without clicking.
    • Check that the link is actually from the uni-wuppertal.de domain.
  • Be careful with file attachments.
    • If in doubt, do not download or open any files.
    • Check with the sender via a different channel to confirm whether they have sent you a file.
  • We have highlighted the points mentioned above in our sample phishing email.

You can report spam and phishing emails to spam[at]uni-wuppertal.de.

Please always forward the suspicious emails as attachments. This is the only way to ensure that all relevant information is retained so that technical measures can be taken if necessary and so that our spam filter can be trained.

In most email programmes, you can follow these steps to send an email as an attachment:

  1. Create a new email.
  2. Drag the message you wish to attach from the message list into the new email
    1. In Outlook, the email is attached as an ‘Outlook item’

    2. In Thunderbird, the attachment has the extension ‘.eml’

  3. Send the new message with the email attached.

In webmail, proceed as follows:

  1. Click on the email you wish to forward as an attachment.
  2. Then click on the three dots (More options) in the top right-hand corner of the email.
  3. Then click on ‘Download message’. The email will now be saved on your computer (in the Downloads folder).
  4. Finally, compose a new email and attach the downloaded email to it.

Please report any spam or phishing emails in your inbox.

Your spam/phishing report helps us to train our email server’s spam filter and identify a surge in suspicious emails. We issue warnings about widespread spam/phishing emails relating to BUW on the ZIM website and via RocketChat.

Please do not report spam or phishing emails that have already ended up in your spam or junk folder, as these have already been identified as spam or phishing. The email system may also prevent the forwarding of such emails that have already been identified.

If you have accidentally opened an attachment in a phishing email or clicked on a link, please contact ZIM User Support immediately by email or by telephone (+49 (0)202 439 3295). Please describe exactly what happened and also forward the email in question to the User Support team.

It is important to act quickly to prevent data loss!

Depending on what has happened, your university account may need to be locked and a new password set. It may also be necessary to scan your computer with an antivirus programme to check for malware.

The following examples provide an initial overview of the possible immediate measures we will advise you to take:

1. Did you click on a link, but nothing was downloaded and you didn’t enter any details? Close your browser and run a virus scan.

2. Did you click on a link, but nothing was downloaded and you did not enter any account details? Close your browser, run a virus scan and change the password for the affected account.

3. Was a download initiated or a file attachment opened, either instead of or in addition to either of the two scenarios above? Disconnect the device from the internet (including Wi-Fi), delete the file and run a virus scan.