Stay Alert: Increase in Suspicious Phone Calls Targeting University Staff 

rkn5
Friday 21 August 2026
Vishing awareness graphic showing a person wearing a headset seated at a laptop displaying an incoming Microsoft Teams call from an unknown caller. The image includes the text "VISHING (VOICE PHISHING)" and a notebook with the message "Think before you trust."
– Illustration of a vishing (voice phishing) call

In recent weeks, the University has seen an increase in phishing phone calls, also known as vishing (voice phishing). 

These calls are designed to trick staff into sharing information that could be used in future cyberattacks. Callers often pretend to represent trusted suppliers, support teams, or government organisations and may ask questions about University systems, security procedures, contact details, contracts, or hardware. 

What makes these calls convincing is that the caller may already know some information about the University, such as: 

  • The names of University buildings 
  • Device or vendor names 
  • Services used by the University 
  • Names of University colleagues 

This information may have been gathered from public sources or previous scams, and it is often used to make the caller appear legitimate. 

Examples of Recent Vishing Attempts 

Recent reports have included callers claiming to be: 

  • Printer support providers requesting information about printer models, services, or maintenance arrangements. 
  • HMRC representatives asking for financial information and claiming it is needed to process a tax refund. 
  • Trusted University suppliers seeking details about contracts, agreements, and service arrangements. 
  • Vehicle management companies asking about University vehicle fleets used by Estates, IT Services, Security and Response, and other departments. 

Remember: if a caller requests information that seems unusual, unnecessary, or sensitive, take a moment to verify who they are before sharing any details.

What to do if you think you are receiving a vishing call? 

If you receive a call that you suspect may be a vishing attempt, politely end the conversation by explaining that it is not a convenient time and ask the caller to contact you again later. 

Once the call has ended, please report it to the IT security team so that we can investigate and take any necessary action. 

In these scenarios, always err on the side of caution, it is better to end the call and report it, than continue the call and put the University, staff, and students at risk. 

How to Report a Suspicious Call in Microsoft Teams 

If you receive a suspicious call through Microsoft Teams, please report it and provide as much information as possible. 

To report a call in Microsoft Teams: 

  1. Open Call History in Microsoft Teams. 
  1. Locate the suspicious call. 
  1. Select the three dots (…) next to the call. 
  1. Choose Report Call

Provide any relevant details about the call before submitting the report. 

Microsoft Teams call history showing recent incoming, outgoing, and missed calls from "Caller 1." An options menu is open for a selected call, displaying actions including Call back, Chat, Remove from view, Add to speed dial, Add contact, and Report call.
– Image from Microsoft Teams of a call history log with the option to report a call.
Dialog box titled "Report call" showing options to report an outgoing call to Caller 1. A dropdown menu is set to "Security concern - Spam, phishing, or malicious call", with an optional text field for additional explanation. Informational text at the bottom explains that call details may be shared with Microsoft to improve detection and protection against suspicious calls. Cancel and Report buttons appear at the bottom right.
– Screenshot of the reporting call dialogue box on Microsoft Teams

What Happens After You Report? 

Reports are reviewed by StACSIRT (St Andrews Computer Security Incident Response Team). The team may contact you if additional information is required as part of their investigation. 

If you receive a suspicious call on your personal mobile phone that relates to the University, please email [email protected] with any relevant details. 

Thank You for Staying Vigilant 

Cybersecurity is everyone’s responsibility, and your awareness helps protect the University from cyber threats. 

If you have any cybersecurity concerns or questions, please contact [email protected]. You can also use the ‘Report Phishing’ button to report suspicious emails. 

Thank you for helping keep the University secure. 

Related topics

Subscribe to the IT Services blog

Enter your email address to subscribe to this blog to receive notifications of new posts.