When to Stop and Ask
Most of this month has been about recognizing risk. This week is about the two seconds after you recognize it, when you decide whether to ask someone or handle it yourself.
That decision gets made under pressure, usually with a nagging sense that asking will look like you could not figure it out. Security teams would far rather answer a question about a message that turned out to be fine than open an investigation into one that was not.
Reporting Early Changes the Outcome
The clearest evidence of this comes from the FBI’s Internet Crime Complaint Center. When someone reports a fraudulent wire transfer quickly enough, IC3’s Recovery Asset Team can trigger a process called the Financial Fraud Kill Chain, contacting the receiving bank directly and asking it to freeze the funds before they move.
In 2025, the team acted on nearly 3,900 incidents involving about $1.16 billion in attempted theft and froze roughly $679 million of it, a success rate of 58 percent.
That number only applies to money the FBI heard about in time. The mechanism works directly with financial institutions, so speed matters. The sooner a fraudulent transfer is reported, the better the chance that funds can be frozen before they move beyond reach.
The same principle holds for everything else. A password reported as possibly compromised on Tuesday afternoon is a password change. The same password reported the following Monday may be a month of attacker access to look through.
Verify Before, Not After
Asking is not only for after something has gone wrong. The higher-value moment is before.
The 2026 Verizon Data Breach Investigations Report found the human element present in 62 percent of breaches, while pretexting has become a more common initial-access vector in ransomware and extortion attacks. These attacks build a credible scenario or relationship before the eventual request is made. Third-party involvement now appears in 40 percent of education breaches, meaning a message from a legitimate vendor contact may be coming from an account that is no longer under that vendor’s control.
Neither of those is something you can resolve by reading the message more carefully. Both are resolved by verification through a separate channel.
Moments Worth Pausing For
- Someone asks you to change payment information, banking details, or direct deposit.
- Someone asks for your password, an MFA code, or access to your account.
- A wire transfer, payment, or purchase request arrives outside the normal process.
- You are asked to share personal or sensitive data, including by someone you know.
- You are about to use a new tool, application, or AI service for university work.
- A message asks you to keep the request between the two of you.
- You notice you are moving faster than you normally would because someone told you it was urgent.
How to Verify, and Where to Report
- Verify using contact information you already have. A phone number printed in a suspicious message is part of the suspicious message.
- Call instead of replying. An attacker who controls an inbox also controls the replies that come back to you.
- Report suspicious messages through your institution’s reporting process rather than simply deleting them.
- Raise the question before you act rather than after. Asking costs a minute, and the alternative can cost months.
- If money has already moved, report it immediately and file a complaint at ic3.gov. Fraudulent funds can move quickly, so report the transfer immediately rather than waiting to investigate it first.
Closing Out the Month
Nothing covered over these five weeks required technical expertise. Know what is likely, know the rules, keep the habits that pay off, recognize the tells, and ask when something does not fit. That is most of it.
Next year’s breach reports will describe attacks that look a lot like this year’s. The people who stay out of those numbers are usually the ones who slowed down long enough to ask a question.
Thank you for participating this month. If you have a question about a message, a request, or a tool, the Office of Information Security would rather hear it early than late. For account, device, or general technical issues, contact your campus help desk. A full list of campus help desk contacts is available on the Universities of Wisconsin IT Help Desks page.