Test Your Cyber Knowledge
Participate in Duke’s annual Cyber Bowl competition Oct. 1-31.
Help Duke Win
Sam Naim, Security Operations Analyst for Duke’s IT Security Office, said students clicked on the link more than other groups at Duke, which led to several chagrined posts on social media.
“Why is this believable 😭,” one student wrote online.
It was intended to be.
Every October, during Cybersecurity Awareness Month, OIT emphasizes that staff, faculty and students should pause before they click on emails. Throughout the year, OIT sends phishing test emails to remind the Duke community of the need to remain watchful.
Phishing for Your Data
During an average month, roughly 105 million emails come to Duke email addresses. Thanks to security systems that detect malware or phishing attempts, 66 million of those messages are automatically blocked.
But that means 39 million emails are delivered, and not all of them are legitimate.
“That’s why catching phishing emails is so hard,” Naim said. “It’s really a cat and mouse game.”
And now, with attackers using artificial intelligence to create and distribute mass amounts of messages to email addresses, phishing attempts are becoming even more difficult to catch. According to cybersecurity company CrowdStrike, in 2025 there was a 69% increase in attacks from AI-enabled adversaries. Attackers used AI to create fake personas, write scripts or text used for the phish and aid in the collection of information. Among the top 10 industries targeted by attackers, healthcare was fifth with 10% of all targeted emails while academics was ninth, with 4%.
“The landscape of phishing is changing a lot, it’s no longer the ‘Prince of Nigeria scam’ that seems really fishy,” said Gaylynn Fassler, Information Security Analyst for Duke Health Technology Solutions, referencing a common scam email tactic from years ago. “They absolutely are using AI to their advantage.”
Which is why Duke OIT uses real-life examples in its phishing tests to encourage vigilance.
“We’re not trying to be harsh. We’re not trying to scare people,” Fassler said. “We’re just trying to get them to stop and think before they click – that’s the goal.”
Become a Cybersecurity Ambassador

In July, an email arrived in the inboxes of staff, faculty and students from “Duke Entrepreneurs,” encouraging everyone to “Join us for an evening with industry leaders.” All you had to do was click on the Paperless Post link to “LOGIN TO RSVP” for the Sept. 16 event.
Except, of course, it wasn’t real. It was a phishing test that fooled a lot of employees with a real example that has been circulating recently: phony online invitations.
Naim leads a team of Cybersecurity Ambassadors, which is open to staff and faculty to join, who help distribute cybersecurity messages to the Duke community or encourage adoption of a new security initiative.
They can also contribute phishing test ideas through the “Suggest a Phish” channel on Teams. Ideas range from promises of a free gift, to an overdue bill that needs immediate attention, to a necessary upgrade to your computer software – all available if you only click one button in an email.

Over the past six years, the Duke staff and faculty click rate on phishing tests has ranged from 3% to 13%, with the reporting rate by clicking “Report Phishing” in Outlook ranging from 13% to 34%.
“Thankfully, we’re showing some improvement,” Naim said.
Even so, Naim encourages three pieces of advice:
- Pause before you click. Be wary of unexpected emails. Report any suspicious emails.
- Protect your NetID. Use a strong, unique password and never share verification codes. Only approve a Duo request when you’ve just initiated a login and deny unexpected prompts.
- Keep your devices updated. Enable automatic updates on your phone, laptop and browser.
Because, Naim said, “IT security is a community-led effort.”
Send story ideas, shout-outs and photographs through our story idea form or write working@duke.edu.
Follow Working@Duke on X (Twitter), Facebook and Instagram and subscribe on YouTube.
