[Phish Alert] $3.45 FAILED – OVERDUE FEE ALERT

This article explains a phishing email that attempts to impersonate Montclair student communications by using university branding, Red Hawk references, and an internal-looking email address. It highlights warning signs such as incorrect department names, generic greetings, personal sender accounts, and malicious links that direct users to sites requesting sensitive personal information.

Phish Alert Button logo that says Phish Alert
Screenshot of fake overdue fee alert email. Screenshot of phishing page requesting personal information. Screenshot of phishing page requesting personal information.

Why this looks valid:

  • Email is coming from an internal email address
  • Student Communications and MSU logo utilized
  • Email says Red Hawk

Why this is phishing?

  • Email address is a personal account not associated with Red Hawk Central or Student Communications
  • Email says Red Hawk Center and not Red Hawk Central
  • Link is malicious and points to webpages asking for personal information
  • Greeting is generic, “Dear Montclair.edu”

Additional Notes

  • Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
  • Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
  • Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
  • Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.

Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!

More News & Stories