Latest Threats
Cyber threats evolve fast—stay in the know with our latest updates to keep your defenses strong.
How to spot a Phishing Email: The Quick Checklist
- Sender Email: Check if the domain matches the legitimate organization (e.g., “@fitnyc.edu” vs. a fake one “@fit12-school.com”).
- [EXT] External Tag: If marked [EXT], the email is coming from outside FIT. This is a signal to proceed with extra caution.
- Too Good to Be True?: Offers for high-paying jobs without interviews or experience are major warning signs.
- Urgency: Watch for pressure tactics like “respond quickly” or “deposit now.”
- Personal Info Requests: Legit employers won’t ask for sensitive data like banking info over email or text.
- Payment Requests: Be suspicious if they want you to return money or make purchases with a check they sent.
Verify Before Acting: Always check the legitimacy of the job offer by contacting the company directly through official channels. RED FLAG: the email doesn’t name the company or doesn’t appear in a web search.

Beware of Fake Text Messages
We received a report of an FIT alumnus who received a text message from someone pretending to a high level executive at FIT. We want to alert you of the dangers of smishing (text message phishing) and to remind you that official college communication is never sent in the form of a text message.“SMS” phishing […]

Beware of blank subject lines in emails
We have received reports of some FIT employees receiving emails with blank subject lines or one character subject lines with no content in the body of the email. Cybersecurity researchers have reported that blank, unsolicited emails are often an early sign of a potential future phishing attack. Cyber gangs will often put feelers out to […]

Tax Refund Phish
What happened?Over the weekend and this morning, FIT (and many of our peer SUNY campuses) received emails from several senders all purporting to represent the IRS, with a subject line of “Recalculating Your Tax Refund Payment.” The emails contained a click button that brings users to a site that looks like an IRS.gov site, but […]