Phone, Zoom, & Teams Safety Guide

Vishing 

Vishing (voice phishing) is the telephone equivalent of email phishing. Attackers can use voice calls or even AI-generated voice clones to trick victims into revealing sensitive information, transferring money, or installing malware. These “deepfake” voices can sound indistinguishable from the real person, making verification critical. 

How to Handle Vishing 

If you suspect a call is a vishing on a Clark College device, follow these protocols: 

How to Handle Deepfakes 

Attackers are increasingly using AI to generate realistic voice recordings of executives or family members. To defend against this threat: 

    • Establish a Verification Code: Create a pre-agreed “safe word” or verification phrase. If the caller cannot provide it, the request is fraudulent. 
    • Secondary Channel Verification: Always verify urgent financial or sensitive requests via a different medium (e.g., a text message or a call to a known internal extension) before acting.  
    • Training: Education others around you that voice alone is no longer proof of identity. 
    • Report the Incident: Always report suspected deepfake incidents by following the steps on the Report an Incident page. 

 

Smishing 

Smishing (SMS phishing) is the use of text messages to trick recipients into revealing sensitive information, downloading malware, or visiting fraudulent websites.  

Here are some common smishing tactics: 

How to Handle Smishing 

If you receive a suspicious text message on a Clark College device, follow these steps to protect yourself: 

    1. Do Not Click Links: Never tap on links in unsolicited texts, even if they appear to come from a legitimate source. Hovering isn’t an option often on mobile, so assume the link is malicious until proven otherwise. 
    2. Do Not Reply: Replying with “STOP,” “NO,” or even “Who is this?” confirms to the attacker that your number is active, which can lead to more spam or targeted attacks. 
    3. Verify Independently: If the message claims to be from a company, contact them directly using the official phone number or website listed on their official site. Do not use the contact info provided in the text. 
    4. Block the Number: Use the blocking feature on your phone or in Zoom to prevent future messages from that specific number by following these steps: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0058630
    5. Report the Message: Report the smishing message by following the steps on the Report an Incident page

 

Video Conferencing 

Zoom-bombing or meeting hijacking occurs when an unauthorized participant joins a private meeting and disrupts it with inappropriate content, harassment, or offensive images. Here are some ways that it happens: 

How to Handle Zoom-Bombing & Meeting Hijacking 

    1. Remove the Intruder: As the host, immediately remove the unauthorized participant from the meeting.

      Follow these instructions to remove an intruder in Microsoft Teams: https://support.microsoft.com/en-US/Outlook/remove-a-person-from-a-meeting

      Follow these instructions to remove an intruder in Zoom: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065566

    2. Lock the Meeting: Enable “Lock Meeting” (if possible) to prevent anyone else from joining.

      Follow these instructions to lock a meeting in Microsoft Teams: https://support.microsoft.com/en-us/teams/meetings/lock-a-meeting-in-microsoft-teams

      Follow these instructions to lock a meeting in Zoom: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061231

    3. Enable Waiting Rooms: Ensure all future participants must be admitted by the host before entering. 

    4. Change the Meeting ID: If the link has been compromised, end the current meeting and start a new one with a fresh, unique ID and password. 

    5. Report Abuse: Report the meeting hijacking incident by following the steps on the Report an Incident page.

Video Conferencing Guidelines 

To prevent Zoom-bombing and meeting hijacking, adopt these habits: 

 

Contact Us 

General Inquiries: For non-urgent questions, email infosec@clark.edu

Report an Incident: To report an information security incident, please visit the Report an Incident page

 

Additional Resources

Report an Incident

Free InfoSec Resources

Changing Your Password

Secure Passwords Guide

Multi-Factor Authentication Guide

Email Safety Guide

Internet Safety Guide

Physical Threats Safety Guide