[PHISH] Item shared with you: “-TCNJ- Important Classification Compensation and Benefit System”

An employee impersonation email is making the round this morning.  Attacker is leveraging the Google Forms environment to send a fake compensation document out.  By using the Google infrastructure it appears legitimate and gets past any initial filters.  Notice in the email body however the senders true email address is revealed.  Please be thorough when viewing any emails and ensure they are from the sender it appears to be before clicking on any links.  

Clicking the link within the email will then take you to a Google doc that contains a link which leads to a Google form that requests your username password and Duo code.  Notice the logo for TCNJ on this form page is incomplete and quite blurry, indicating it was saved from the internet rather than being an official TCNJ logo image.   This attack was somewhat polished and by using multiple branded documents tried to add legitimacy to its content.  If you are unsure or if you happen to fall victim to one of these attacks, please reach out to us at phish@tcnj.edu.  Thank you.

 

Top

[kicknav]