[Phish Alert] Activate 2FA/Enable Two-Factor Authentication

This article explains a phishing email that impersonates Montclair faculty or staff and uses branding and QR codes to appear legitimate

Phish Alert Button logo that says Phish Alert
Screenshot of a phising email posing as Montclair with a QR code.

Why this looks valid:

  • Attacker uses legitimate Montclair faculty/staff names
  • Contains the Montclair logo

Why this is phishing?

  • QR code link is fraudulent
  • Email Subject changes:
    • [Activate 2FA for Stronger Security]
    • [Protect Your Account: Activate 2FA Now]
    • [Safeguard Your Account: Enable 2-Factor Authentication Today]
    • [Boost Security: Enable Two-Factor Authentication]
  • Spelling errors: No space between QR and code as well as (2SV) having a space
  • Email address is external
  • Name in signature is not similar to the one in the From alias

Additional Notes

  • Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
  • Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
  • Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
  • Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.

Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!

More News & Stories