[Phish Alert] Your Account Deactivation
This phishing text message impersonates Montclair State University and uses urgent language to pressure users into acting quickly before their account is supposedly disabled. The message is part of a broader phishing campaign designed to steal login credentials, passwords, and Duo MFA codes by creating a false sense of urgency and trust.
Why this looks valid:
- Text says it’s coming from Montclair State University.
Why this is phishing?
- Text was sent in response to a previous phishing attack. [Please see Montclair State University Notice – September 10, 2025: Action Required Now!!!]
- Don’t share your passwords, duo codes or personal information with anyone. IT will never ask you for your login credentials.
- Attacker attempts to rush the user to act fast or their account will be shut down.
Additional Notes
- Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
- Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
- Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
- Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.
Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!
- Published