Alert image

Falls City Public Schools Stakeholders,

We are seeing an increase in phishing emails in our area, including some sent from legitimate staff email accounts that have been compromised. That means an email can come from someone you know, showing their real school email address, and still be a phishing attempt. Although we have security measures in place to try and prevent these things from happening, we are all human and on occasion our accounts may be compromised. When this happens, our IT staff and Educational Service Unit are notified, suspend the accounts, and reactivate the accounts once they feel the accounts have been secured. We don't want to discourage guardians from opening emails from teachers, but we do want encourage everyone to please take an extra few seconds before clicking a link, opening an attachment, scanning a QR code, or entering your password. Here are a few reminders:

1. The request is unusual for the person sending it

Even if you recognize the sender, ask yourself:

  • Does this person normally send me things like this?

  • Were you expecting this document, invoice, shared file, or request?

  • Does the wording sound like them?

  • Are they unexpectedly asking you to sign in, click a link, buy something, or send information?

2. The email creates urgency or pressure. Attackers want you to act before you think.

Be suspicious of messages such as:

“This needs to be completed immediately.”

“Your account will be disabled today.”

“Please review this document ASAP.”

“Are you available? I need a quick favor.”

3. A link asks you to sign in

Be especially careful with links claiming to be Google Drive, Google Docs, Microsoft 365, DocuSign, voicemail, payroll, or another familiar service.

On a computer, hover your mouse over the link without clicking it. Gmail will show where the link actually goes.

If you weren't expecting the message, don't use the link. Go directly to the service yourself instead.

4. You're asked for your Google password

A common attack sends you to a convincing copy of a Google sign-in page.

If you click something and suddenly need to enter your school Google username and password, stop and make sure you are actually on a Google website before entering anything.

5. Be careful with QR codes

QR-code phishing is increasingly common. A QR code can hide the destination just like a link can.

Don't scan an unexpected QR code from an email simply because it appears to come from someone you know.

6. Gmail gives you a warning — pay attention to it

Google may display warnings about suspicious messages, unusual senders, dangerous links, or attachments.

Don't ignore or click through these warnings just because you recognize the sender's name.

Remember: the sender may really be a FCPS employee

One of the most important things to understand is that attackers sometimes gain access to a real employee's Google account. They can then send phishing emails from that person's actual account.

So instead of asking only:

“Do I recognize the sender?”

also ask:

“Does this message make sense coming from this person?”

When in doubt, don't click

If something doesn't feel right:

  1. Don't click the link, attachment, or QR code.

  2. Don't reply to the suspicious email to verify it.

  3. Contact the sender another way — call them, talk to them in person, or start a new email to their known address.

We hope this helps all of our stakeholders keep their accounts safe and secure!