詐騙(釣魚)信件宣導說明 Phishing/Scam Email Awareness Notice
發布日期 2026-07-17 13:10:00
近期AI詐騙(釣魚)信件手法頻傳,請教職同仁提高警覺,切勿輕易受騙。經查證確認遭詐騙(釣魚)成功者,將依規定強制安排資安教育訓練。請大家詳閱以下說明並多加留意:
AI詐騙(釣魚)信件的演變速度極快,但並非無法防範,重點提醒如下:
- 切勿在資訊服務入口網以外的網頁輸入工作帳號密碼,這是最基本的防護原則。本校各單位網站網址皆為「編號.wzu.edu.tw」格式,例如資教中心為 c013.wzu.edu.tw、教務處為 c003.wzu.edu.tw,此規則從未變更。若收到的連結網址非本校網址,應立即提高警覺。
- 是否收到垃圾郵件與信箱容量是否已滿無關,也不會因為輸入帳號密碼而增加容量或減少垃圾郵件,請勿被此類說法誤導。
- 務必對自身業務範疇有基本認識,並確認學校是否確有該單位。本校信件署名皆為單位名稱或承辦人姓名(含分機號碼),若信件內容無法明確辨識對口單位或承辦人身分,請務必提高警覺,切勿輕信。
社交工程防範基本觀念:
請勿輕信突如其來的要求而任意輸入帳號密碼,以免洩漏重要資訊。收到可疑訊息時,應先透過其他管道(如電話)向當事人或相關機構查證,切勿直接回覆或點擊信件中的連結。
此外,公務信件應與私人信件明確區隔,不得將公務信箱設定轉寄至個人信箱(如Gmail)。依教育部「教育體系電子郵件服務與安全管理指引」規定,公務或專用電子郵件信箱不得設定轉寄至外部信箱,敬請確實遵循,以降低資訊外洩風險。
如有相關問題,歡迎來電本校資教中心資安專職人員許家耀先生,分機2815。
Recently, AI-generated phishing (fraudulent) emails have become increasingly frequent. All faculty and staff are urged to remain vigilant and avoid falling victim to these scams. Anyone confirmed to have been successfully phished will be required to attend mandatory information security training in accordance with university regulations. Please review the following guidelines carefully:
AI phishing emails are evolving rapidly, but they can still be prevented. Key points to note:
- Never enter your work account credentials on any website other than the official Information Services Portal. This is the most fundamental protective measure. All university department websites follow the format "[code].wzu.edu.tw" — for example, the Information & Instructional Technology Center is c013.wzu.edu.tw, and the Office of Academic Affairs is c003.wzu.edu.tw. This naming convention has never changed. If a link directs you to a URL that does not follow this pattern, treat it with caution.
- Receiving spam/junk emails has nothing to do with mailbox storage capacity. Entering your password will not increase your storage quota or reduce the amount of spam you receive — do not be misled by such claims.
- Make sure you have a basic understanding of your own work unit, and verify whether the sending department actually exists at this university. All legitimate emails from the university are signed with the department name or the handling staff member's name (including extension number). If an email's sender or department cannot be clearly identified, remain highly cautious.
Basic Principles of Social Engineering Prevention:
Do not readily trust unexpected requests that ask you to enter your account credentials, as this can lead to the disclosure of sensitive information. If you receive a suspicious message, verify it first through another channel (such as a phone call) with the person or organization involved — do not reply to or click links within the suspicious email directly.
In addition, work-related email should be kept separate from personal email. Do not set up auto-forwarding from your official university mailbox to a personal mailbox (e.g., Gmail). Per the Ministry of Education's "Guidelines for Email Services and Security Management in the Education System," official or dedicated email accounts must not be configured to forward messages to external mailboxes. Please strictly comply with this requirement to reduce the risk of information leakage.
If you have any questions, please contact Information Security Officer, Information and Instructional Technology Center, at extension 2815.


