[Phish Alert] Staff Appreciation and Service Awards – Eligibility Confirmation
This phishing email appears legitimate because it is signed by university leadership, references a familiar staff event, and uses formal, professional language consistent with official communications.
Why this looks valid:
- High Authority: It is signed by the actual president’s name and mentions the Staff Council, making it seem like a top-level, official university communication.
- Familiar Topic: The subject is the Staff Appreciation and Service Awards, an event every staff member knows about, making the request seem normal.
- Professional Tone: The language is formal and polite, perfectly mimicking genuine communications from the university administration.
Why this is phishing?
- Suspicious Link: It directs you to an unknown “Eligibility Portal” instead of Workday.
- Wrong Department: Confirming service eligibility is an HR/Payroll function, but this request is supposedly coming from the Staff Council/President.
- Branding Check: (This is a subtle, but key check): Official communications strictly use Montclair or Montclair State University. If the body contained unusual variations (e.g., “Montclair University” or inconsistent capitalization), it would be a major red flag. (Note: While this email uses the correct branding, scammers often slip up, making this a necessary check.)
Additional Notes
- Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
- Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
- Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
- Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.
Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!
- Published