Spot it first
Before you report, check the signs. A phishing email usually has one or more of these:
- Urgent or threatening language ("your account will be closed")
- A sender address that looks almost right but is not @scu.edu.au
- A generic greeting instead of your name
- A link that goes somewhere unexpected when you hover over it
- A request for your password or personal details
Report it with the Outlook button
The fastest way to report a suspected phishing email is the Report Phishing button in Outlook.
- Open the suspicious email in Outlook.
- Do not click any links or open attachments.
- Select the email in your inbox (leave it unopened where possible).
- Click Report Phishing in the Outlook toolbar, or select the email, right-click, and choose Report → Report Phishing.
- Outlook moves the email to your deleted items and sends a copy to Microsoft and the SCU security team.
No Report button?
If you do not see the Report Phishing button, forward the email to the Technology Services Service Desk at servicedesk@scu.edu.au as an attachment, then delete the original.
You already clicked or entered your password
Do not panic. Act quickly.
- Change your SCU password immediately at mysignins.microsoft.com/security-info.
- If you reuse that password anywhere else, change it there too.
- Run a scan with your antivirus software.
- Report the incident to the Technology Services Service Desk.
What happens after you report
The security team reviews reported emails. If it is a real phishing attempt, they block the sender and scan for other staff or students who may have received it. Reporting helps protect the whole University, not just you.