[Phish Alert] Montclair State University Payment Returned.
This article explains a phishing email that impersonates Montclair State University using internal-looking addresses and branding to appear legitimate.
Why this looks valid:
- Email is coming from an internal email address
- Montclair State University logo is used
- Email name is Montclair State University
- Link within email is showing as MSU website
Why this is phishing?
- Email address is a personal MSU account
- Sense of Urgency: Stating you’ll lose access to you account
- Link is actually malicious and not associated with MSU. Using the hover over technique it points somewhere else.
- Spelling: Attacker uses “C*V*V #” on the malicious website instead of CSV
- Personally Identifiable Information (PII): Attacker is requesting SSN
Additional Notes
- Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
- Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
- Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
- Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.
Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!
- Published
- Type
- Topic