Rise in Phishing Attempts Impersonating Trusted Services
Rise in Phishing Attempts Impersonating Trusted Services
Phishing attempts are increasingly using familiar names, services and notification formats to make malicious emails more difficult to recognize. Seton Hall’s IT Security team recently identified a phishing campaign targeting the University community that demonstrates how attackers use this approach to impersonate trusted technology and prompt recipients to take action.
The campaign included emails designed to resemble legitimate Microsoft Teams notifications. By incorporating recognizable Microsoft branding and familiar communication formats, the messages were intended to appear credible and make recipients less likely to question them before responding or selecting a link.
The tactic extends beyond Microsoft Teams. Cybercriminals may imitate Outlook, OneDrive, SharePoint, DocuSign, Zoom, Google and other commonly used services or use the names of colleagues and familiar contacts. Messages may refer to a plausible meeting, shared document or account activity, often adding urgency to encourage recipients to act without closely examining the email.
If a message appears to come from someone familiar but the request seems unusual, IT Security recommends verifying it separately through a trusted communication method rather than using links or contact information provided in the email. This is particularly important when a request involves signing in or providing sensitive information. Because legitimate accounts can also be compromised and used to distribute phishing messages, a recognizable sender address does not necessarily mean the communication is safe.
Microsoft and the University’s email security systems automatically quarantine many potentially malicious messages. When an email is placed in quarantine, the option to release it does not mean it has been determined to be safe. Recipients should confirm that they recognize the sender and were expecting the communication before releasing the message, then continue to use caution with any links, attachments or requests it contains.
As phishing attempts become more effective at imitating familiar tools and communications, IT Security encourages members of the University community to take an extra moment before acting on an unexpected email. Reviewing the sender’s complete address, hovering over links to check their true destination and considering whether the communication was expected can help identify warning signs that might otherwise be overlooked.
Suspected phishing emails should be reported through the University’s phishing-reporting process so IT Security can investigate. Anyone who has clicked a suspicious link, entered University credentials or otherwise interacted with a potentially malicious message should contact IT Security immediately.
Taking the time to question an unexpected request and verify it through a trusted source can prevent a convincing phishing attempt from becoming a compromised account and help protect University information.
Categories: Science and Technology
Related Stories
Cybersecurity
Côte d’Ivoire calls for inclusive and resilient digital future at ITU WTPF
1 day ago
Cybersecurity
UNOOSA highlights space traffic coordination and African participation at Paris Summit
1 day ago
Cybersecurity
Deepfake scams are growing more sophisticated, Arkansas cybersecurity experts warn
1 week ago
Cybersecurity
Hackers, barns, and breakfast: Why agriculture needs cybersecurity
1 week ago
Cybersecurity
Oslo-based Pistachio acquires Hugin.io to expand into cybersecurity compliance
1 week ago
Cybersecurity
‘Not perfectly aligned’ with human values: Anthropic admits security failures behind AI hacking incidents
1 week ago
Cybersecurity
78% of South African SMBs encountered cybersecurity incidents over the past year, Kaspersky research shows
2 weeks ago
Cybersecurity
Doctor's appointment phone call led to data breach
2 weeks ago