[Phish Alert] [Name] shared staff performance and evaluation forms

This article explains a phishing email that impersonates a trusted MSU faculty or staff member and uses legitimate-looking Microsoft 365 forms and university email references to appear authentic.

Phish Alert Button logo that says Phish Alert
Screenshot of a phishing email posing as a staff evaluation form. Screenshot of the page users would see if they opened the phishing email link posing as an evaluation.

Why this looks valid:

  • Email states that it is coming from a faculty/staff member that would have access to these type of files.
  • Email links to a legitimate Montclair email address within the body of the email.
  • Link within email body links to a forms page supported by Microsoft 365.

Why this is phishing?

  • Email is not coming from an official Montclair email
  • Link on form page is coming from another countries domain (i.e. .ru, .de, .jp, etc.)
  • Once the link within the form page is accessed the user is prompted to authenticate via Google in order to gain access to the PDF containing a malicious payload.

Additional Notes

  • Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
  • Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
  • Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
  • Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.

Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!

More News & Stories