[Phish Alert] Your refund has been paid
This article explains a phishing email that impersonates Montclair State University by using familiar university branding and references to payment services like TouchNet.
Why this looks valid:
- Email has the banner and wording of an email coming from MSU
- Link in email states it’s going to TouchNet
Why this is phishing?
- The email addresses utilized are either from an external email address or from an MSU user that would not send this information
- Link goes to BankMobile not TouchNet
Additional Notes
- Remember: Information Technology will never text you. We will also never request your password or Duo codes, ever.
- Information Technology will not ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.
- Do you think you’ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk.
- Use the Knowbe4 Phish Alert Button (PAB) to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to phishfiles@montclair.edu.
Always use the “hover over” technique to check web links before clicking! For more security tips please visit the Phish Files!
- Published
- Type
- Topic