[Phish Alert] REF: Mail Draw Statement
This article explains a phishing email that impersonates a faculty or staff member and uses vague, confidential-sounding language to pressure users into clicking a link.
Why this looks valid:
- Email states it’s coming from a faculty/staff member.
- Email body states that the file is confidential and is only accessible via link.
Why this is phishing?
- Email subject and body are vague to entice an unsuspecting user to click the link.
- Link available via the button in this email does not lead to a legitimate location.
- Once link is interacted with it leads to a fake Google login page to capture login credentials.
Additional Notes
- Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
- Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
- Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
- Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.
Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!
- Published
- Type
- Topic