Phish Files is your go-to hub for staying informed about phishing and email-based threats targeting our campus community. By combining real-world examples with practical guidance, this space helps you recognize suspicious messages, understand how attacks work, and know what to do when something doesn’t look right.

Here, you’ll find current phishing trends, examples of recent scams, and quick tips to help you spot red flags like unexpected requests, urgent language, or unfamiliar links. The goal is simple: build awareness so you can make informed decisions and avoid falling for common tactics.

Phishing is one of the most frequent cybersecurity threats—but it’s also one of the easiest to stop when you know what to look for. Stay alert, stay informed, and when in doubt, report it.

Phish Alert Button (PAB)

Anti-Phish Arsenal

 Your toolkit for staying safe online. Download and use these resources to strengthen your cybersecurity habits.

Breaking News

What is Phishing?

Phishing is a cyber scam where attackers impersonate trusted sources, like Montclair, a professor, or a well-known company, to trick you into sharing sensitive information such as passwords, financial details, or login credentials. These scams can come through email, text messages, phone calls, or fake websites and often create a sense of urgency to catch you off guard.

TypeWhat It Looks LikeExample
Email PhishingFake emails that appear legitimate and try to get you to click links or enter credentials“Your account will be locked—verify your login here”
Spear PhishingTargeted emails using personal details to seem trustworthy“Hi [Name], can you review this attached document?”
Job ScamsFake job offers asking for payment or sensitive information“You’ve been hired—submit a processing fee to begin”
Tech Support ScamsFake IT or system alerts requesting access or passwords“IT detected an issue—log in immediately to fix it”
Credential HarvestingFake login pages designed to steal usernames and passwordsA login page that looks like your school portal but has a fake URL
SmishingText messages with suspicious links or urgent requests“Your package is delayed—track it here”
VishingPhone calls impersonating trusted organizations“This is IT Support—confirm your password to continue”

How to Spot Phishing

  • Check sender address carefully – verify the email domain and sender identity.
  • Look for spelling or grammar errors – poor writing can indicate a phishing attempt.
  • Watch for urgency or threats – be cautious of pressure tactics or scare language.
  • Be cautious with links and attachments – don’t click or open anything unexpected.
  • Avoid sharing passwords or Duo codes – never provide credentials or authentication codes.
  • Be wary of generic greetings (“Dear user”) – impersonation emails often avoid using your name.
  • Type URLs directly instead of clicking links – manually enter known websites into your browser.

Watch for “[EXTERNAL]” in Subject Lines

Emails from outside the university are labeled with [EXTERNAL] in the subject line.

Important Notes

  • External does NOT automatically mean malicious
  • Always verify before clicking links or downloading attachments
  • Never share passwords or Duo codes—even if marked [EXTERNAL]

Protecting Personally Identifiable Information (PII)

The university will never ask you to provide:

  • Your password
  • Duo MFA verification codes
  • Sensitive personal information through unsolicited email or text messages

If something feels suspicious, verify before responding.

Personally Identifiable Information (PII) is any information that can identify you or someone else. Criminals often target PII through phishing emails, fake websites, text messages, phone calls, and social engineering scams.

Examples of PII include:

  • Full name
  • Date of birth
  • Home address
  • Phone number
  • Personal email address
  • Student or employee ID number
  • Social Security number
  • Driver’s license or passport information
  • Banking or payment information
  • Login credentials and MFA codes

Stolen personal information can be used to:

  • Access university accounts
  • Commit identity theft or financial fraud
  • Send convincing phishing messages
  • Impersonate students, faculty, or staff
  • Gain access to university systems or sensitive data

Even small details shared online can help attackers build a more convincing scam.

Phishing Emails

Messages pretending to be from:

  • IT or Help Desk
  • Payroll or HR
  • Financial Aid
  • Banks or delivery services
  • Faculty, supervisors, or university leadership

These emails may ask you to:

  • “Verify your account”
  • Reset your password
  • Open an attachment
  • Click a login link
  • Provide personal information

Smishing (Text Message Scams)

Attackers may send texts about:

  • Package deliveries
  • Account suspensions
  • MFA verification
  • Tuition or payment issues

Social Engineering

Someone may call or message pretending to be:

  • Technical support
  • A professor or department
  • A student employee
  • A vendor or partner organization

Their goal is often to pressure you into sharing information quickly.

Stop and Verify

Before sharing personal information:

  • Verify the sender or caller independently
  • Be cautious of urgent or threatening language
  • Double-check email addresses and website URLs

Protect Your Accounts

  • Use strong, unique passwords
  • Enable Multi-Factor Authentication (MFA) on all accounts
  • Never share MFA codes with anyone

Be Careful with Links and Attachments

  • Do not click unexpected links
  • Avoid opening attachments from unknown senders
  • Type important websites directly into your browser

Limit What You Share

Only provide information when necessary and through trusted university systems.

Be cautious if a message:

  • Creates urgency or fear
  • Requests passwords or MFA codes
  • Asks for personal or financial information
  • Forms that ask for passwords, codes, etc.
  • Contains spelling or grammar errors
  • Comes from an unusual sender
  • Includes suspicious links or attachments

Next Steps After a Scam

What to do if you’ve interacted with a phishing scam or shared sensitive information—follow these steps to secure your accounts, report the incident, and minimize potential impact.

Avoid reacting quickly and assess the situation before taking action.

Immediately update your primary account credentials and any reused passwords.

Go to the NetID Account Management Center.

Approve only legitimate login requests and deny anything unexpected.

Document the incident to support investigation and reporting.

Let us know about the scam as soon as possible.

Learn more about the PAB.

Keep a close eye on logins, transactions, and account changes.

Alert them right away to protect your accounts.

Escalate the incident through proper reporting channels if required.

Contact University Police.

Campus Resources

Information Security – Report phishing, compromised accounts, or suspicious activity.

ServiceNow Knowledge Base – Browse helpful articles, guides, and support resources for common IT questions and services.

IT Service Desk – Get help securing your account and restoring access.

NetID Account Management Center – Reset your password.

Phish Alert Button (PAB) – Quickly report suspicious emails from your inbox.

Duo Support (Duo Mobile) – Help with multi-factor authentication setup and issues.

University Police  – Contact for identity theft, financial fraud, cyberstalking, or personal safety concerns.

Report & Recover

Federal Trade Commission – Report fraud and get recovery guidance.

IdentityTheft.gov – Create a recovery plan for identity theft.

FBI Internet Crime Complaint Center – Report cybercrime and scams.

CISA – Access alerts and security best practices.

Have I Been Pwned – Check if your information was exposed in a breach.

Credit Monitoring & Fraud Alerts – Set up alerts or freezes to help protect your identity.

Annual Credit Report – Check your credit reports and monitor for signs of identity theft or fraud.