Posts

Ten Seconds of Doubt: The Signs Worth Slowing Down For

Scams rarely get caught because someone spotted a spelling error. They get caught because someone stopped for ten seconds and noticed that the request did not fit.

That is what a tell is. Not a dramatic red flag, but a small mismatch between what a message asks and how things normally work. The sender who never emails suddenly emails. The invoice that arrives with new banking details. The deadline that leaves no time to check with anyone.

The Scale of It

The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025, the highest number it has ever recorded, with reported losses of $20.877 billion. That is a 26 percent increase over the prior year.

Business email compromise accounted for $3.046 billion of that total from only 24,768 complaints. The ratio is the important part. Business email compromise does not depend on malware or a technical exploit. It depends on a convincing message and a person who acts on it, which is why the average loss runs so high relative to the number of reports.

Phishing and spoofing remained the most frequently reported crime type overall, making up roughly 19 percent of all complaints.

The Delivery Is Changing

The 2026 Verizon Data Breach Investigations Report found the human element present in 62 percent of breaches. Phishing accounted for 16 percent of all breaches, holding steady from the prior year.

What moved is where phishing arrives. In phishing simulations, the median click rate on mobile-centric vectors such as voice calls and text messages ran 40 percent higher than on email. People read a text between meetings and answer a call while walking to one, applying far less scrutiny than they would at a desk.

Pretexting accounted for 6 percent of all breaches and has become a more common initial access vector in ransomware and extortion attacks. In a pretexting attack, the first contact is not trying to get you to click anything. It is establishing a plausible relationship, often by phone, so that the real request later feels routine.

Artificial intelligence has also improved the writing. The IC3 recorded 22,364 complaints with an AI-related descriptor in 2025, representing $893 million in reported losses. It was the first year IC3 tracked AI this way. Awkward grammar and sloppy formatting are no longer reliable tells.

In education specifically, social attacks appeared in 22 percent of breaches. Of those, 81 percent were classic phishing, delivered by email 88 percent of the time.

The Tells That Still Work

The details change constantly. The structure does not. Watch for these.

  • Urgency that discourages verification. A deadline conveniently removes the time you would have spent checking with someone.
  • A change to payment details. A new bank account, routing number, or direct deposit destination is the single highest-value warning sign on this list.
  • A request that skips the normal process. Approvals get routed around, an unusual channel is used, or secrecy is framed as discretion.
  • Gift cards. No legitimate university business is ever conducted in gift cards.
  • A request that does not fit the sender. A dean asking a favor by text message, or a familiar vendor writing from a slightly different domain.
  • Unexpected links and attachments. This includes messages from people you know, whose accounts may already be compromised.
  • Any request for credentials or an MFA code. Nobody legitimate will ever ask you for either one.
  • Pressure applied to you personally. Flattery, confidentiality, and implied consequences are all tools for keeping you from asking someone else.

What to Do When You Notice One

  • Stop before you reply, click, pay, or approve anything.
  • Verify through a separate channel, using contact information you already have rather than what the message provides.
  • Never confirm a payment change by replying to the message that requested it.
  • Treat phone calls and text messages with the same caution you give email.
  • Report the message even if you did not fall for it, because knowing what is circulating helps protect everyone else.

If Something Goes Wrong

If you clicked, replied, entered credentials, or approved a payment and something feels wrong afterward, report it immediately. Speed is the variable that matters most, and next week’s article explains exactly why.

For questions about a suspicious message or a request you are unsure about, the Office of Information Security would rather hear from you early than late. For account or device issues, contact your campus help desk. A full list of campus contacts is available on the Universities of Wisconsin IT Help Desks page.