  {"id":1488,"date":"2026-03-05T12:29:45","date_gmt":"2026-03-05T17:29:45","guid":{"rendered":"https:\/\/www.montclair.edu\/phish-files\/?p=1488"},"modified":"2026-03-18T11:31:18","modified_gmt":"2026-03-18T15:31:18","slug":"watch-out-university-act-now-email-and-follow-up-text-scam","status":"publish","type":"post","link":"https:\/\/www.montclair.edu\/phish-files\/2026\/03\/05\/watch-out-university-act-now-email-and-follow-up-text-scam\/","title":{"rendered":"Watch Out: \u201cUniversity Act Now!!!\u201d Email and Follow-Up Text Scam"},"content":{"rendered":"<h2 data-start=\"82\" data-end=\"104\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.montclair.edu\/phish-files\/wp-content\/uploads\/sites\/290\/2026\/03\/University-Act-now-phish.png\" alt=\"phishing email posing as IT to gain account access.\" width=\"1230\" height=\"529\" \/><\/h2>\n<h2 data-start=\"82\" data-end=\"104\"><strong data-start=\"82\" data-end=\"104\">How It Looks Legit<\/strong><\/h2>\n<ul data-start=\"105\" data-end=\"682\">\n<li data-start=\"105\" data-end=\"272\">\n<p data-start=\"107\" data-end=\"272\"><strong data-start=\"107\" data-end=\"153\">Appears to come from the IT Service Desk:<\/strong> The email is sent from a <strong data-start=\"179\" data-end=\"213\">compromised Montclair account<\/strong>, making it look like it\u2019s coming from someone on campus.<\/p>\n<\/li>\n<li data-start=\"273\" data-end=\"427\">\n<p data-start=\"275\" data-end=\"427\"><strong data-start=\"275\" data-end=\"302\">Urgent account warning:<\/strong> It claims your email will stop receiving messages or be permanently deleted if you don\u2019t verify your account within hours.<\/p>\n<\/li>\n<li data-start=\"428\" data-end=\"545\">\n<p data-start=\"430\" data-end=\"545\"><strong data-start=\"430\" data-end=\"461\">Simple \u201cverification\u201d form:<\/strong> The message links to a Google Form that looks like a quick step to fix the issue.<\/p>\n<\/li>\n<li data-start=\"546\" data-end=\"682\">\n<p data-start=\"548\" data-end=\"682\"><strong data-start=\"548\" data-end=\"575\">Follow-up help by text:<\/strong> In some cases, attackers will <strong data-start=\"606\" data-end=\"643\">text the user pretending to be IT<\/strong> to help \u201cresolve\u201d the account problem.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"684\" data-end=\"704\"><strong data-start=\"684\" data-end=\"704\">How It\u2019s a Phish<\/strong><\/h2>\n<ul data-start=\"705\" data-end=\"1290\">\n<li data-start=\"705\" data-end=\"826\">\n<p data-start=\"707\" data-end=\"826\"><strong data-start=\"707\" data-end=\"743\">Urgency is used to pressure you:<\/strong> The message pushes you to act quickly before your account is supposedly deleted.<\/p>\n<\/li>\n<li data-start=\"827\" data-end=\"978\">\n<p data-start=\"829\" data-end=\"978\"><strong data-start=\"829\" data-end=\"859\">It asks for your password:<\/strong> The Google Form requests your email and password, sometimes labeling the password field as <strong data-start=\"951\" data-end=\"960\">\u201cACP\u201d<\/strong> to disguise it.<\/p>\n<\/li>\n<li data-start=\"979\" data-end=\"1112\">\n<p data-start=\"981\" data-end=\"1112\"><strong data-start=\"981\" data-end=\"1012\">Text message impersonation:<\/strong> Attackers may text you claiming to be IT and ask for your <strong data-start=\"1071\" data-end=\"1109\">password and Duo verification code<\/strong>.<\/p>\n<\/li>\n<li data-start=\"1113\" data-end=\"1290\">\n<p data-start=\"1115\" data-end=\"1290\"><strong data-start=\"1115\" data-end=\"1148\">IT does not operate this way:<\/strong> The IT Service Desk will never ask for your password or Duo code, and does not verify accounts through Google Forms or text messages.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"1292\" data-end=\"1327\"><strong data-start=\"1292\" data-end=\"1327\">What Happens If You Fall for It<\/strong><\/h2>\n<ul data-start=\"1328\" data-end=\"1714\">\n<li data-start=\"1328\" data-end=\"1429\">\n<p data-start=\"1330\" data-end=\"1429\"><strong data-start=\"1330\" data-end=\"1362\">Your credentials are stolen:<\/strong> Submitting the form gives attackers your <strong data-start=\"1404\" data-end=\"1426\">email and password<\/strong>.<\/p>\n<\/li>\n<li data-start=\"1430\" data-end=\"1570\">\n<p data-start=\"1432\" data-end=\"1570\"><strong data-start=\"1432\" data-end=\"1456\">Duo can be bypassed:<\/strong> If you share your Duo code in the follow-up text, attackers can <strong data-start=\"1521\" data-end=\"1567\">complete the login and access your account<\/strong>.<\/p>\n<\/li>\n<li data-start=\"1571\" data-end=\"1714\">\n<p data-start=\"1573\" data-end=\"1714\"><strong data-start=\"1573\" data-end=\"1618\">Your account may be used in more attacks:<\/strong> Compromised accounts are often used to <strong data-start=\"1658\" data-end=\"1713\">send additional phishing emails to others on campus<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"1716\" data-end=\"1730\"><strong data-start=\"1716\" data-end=\"1730\">What To Do<\/strong><\/h2>\n<ul data-start=\"1731\" data-end=\"2048\" data-is-last-node=\"\" data-is-only-node=\"\">\n<li data-start=\"1731\" data-end=\"1782\">\n<p data-start=\"1733\" data-end=\"1782\"><strong data-start=\"1733\" data-end=\"1780\">Do not click the link or complete the form.<\/strong><\/p>\n<\/li>\n<li data-start=\"1783\" data-end=\"1841\">\n<p data-start=\"1785\" data-end=\"1841\"><strong data-start=\"1785\" data-end=\"1839\">Do not respond <\/strong>to text messages claiming to be IT.<\/p>\n<\/li>\n<li data-start=\"1783\" data-end=\"1841\"><strong>Do not forward<\/strong> or respond to the email. Sharing is not caring.<\/li>\n<li data-start=\"1783\" data-end=\"1841\"><strong>Block<\/strong> the phone number.<\/li>\n<li data-start=\"1842\" data-end=\"1935\">\n<p data-start=\"1844\" data-end=\"1935\"><strong data-start=\"1844\" data-end=\"1893\">Report the email using the <a href=\"https:\/\/www.montclair.edu\/information-technology\/security\/pab\/\">Phish Alert Button<\/a><\/strong> or sending screenshots to <a href=\"mailto:phishfiles@montclair.edu\">phishfiles@montclair.edu<\/a>.<\/p>\n<\/li>\n<li data-start=\"1936\" data-end=\"2048\" data-is-last-node=\"\">\n<p data-start=\"1938\" data-end=\"2048\" data-is-last-node=\"\">If you already entered your information, change your password immediately and contact the<strong data-start=\"1938\" data-end=\"2048\" data-is-last-node=\"\"><a href=\"https:\/\/www.montclair.edu\/information-technology\/it-service-desk\/\"> IT Service Desk<\/a>.<\/strong><\/p>\n<\/li>\n<\/ul>\n<h2>Additional Notes:<\/h2>\n<ul>\n<li><strong>Remember<\/strong><strong>:<\/strong>\u00a0Information Technology will never text you. We will also never request your password or Duo codes,\u00a0<strong>ever<\/strong>.<\/li>\n<li>Information Technology will\u00a0<strong data-start=\"1865\" data-end=\"1872\">not<\/strong>\u00a0ask you to verify accounts or submit passwords through unofficial forms or unexpected email links.<\/li>\n<li>Do you think you\u2019ve fallen for a scam? Did you share personal information? Downloaded malicious content? Please contact the IT Service Desk at\u00a0<a href=\"tel:973-655-7971\" class=\"\"><span class=\"a11y-phone-number initialized\" aria-label=\"9 7 3 6 5 5 79 71 \">973-655-7971<\/span><\/a>\u00a0option 1 or email\u00a0<a href=\"mailto:itservicedesk@montclair.edu\">itservicedesk@montclair.edu<\/a>.<\/li>\n<li>Use the\u00a0<a href=\"https:\/\/www.montclair.edu\/information-technology\/security\/pab\/\">Knowbe4 Phish Alert Button (PAB)<\/a>\u00a0to report malicious emails directly to the Information Security team for review. If you are not using the Gmail client please forward the email to\u00a0<a href=\"mailto:phishfiles@montclair.edu\">phishfiles@montclair.edu<\/a>.<\/li>\n<li>Always use the \u201chover over\u201d technique to check web links before clicking! For more security tips please visit our\u00a0<a href=\"https:\/\/www.montclair.edu\/information-technology\/security\/security-tips\/\">Security Tips<\/a>\u00a0page.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>How It Looks Legit Appears to come from the IT Service Desk: The email is sent from a compromised Montclair account, making it look like it\u2019s coming from someone on campus. Urgent account warning: It claims your email will stop receiving messages or be permanently deleted if you don\u2019t verify your account within hours. Simple [&hellip;]<\/p>\n","protected":false},"author":349,"featured_media":1495,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[7],"tags":[],"class_list":["post-1488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-smishing"],"_links":{"self":[{"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/posts\/1488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/users\/349"}],"replies":[{"embeddable":true,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/comments?post=1488"}],"version-history":[{"count":3,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/posts\/1488\/revisions"}],"predecessor-version":[{"id":1555,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/posts\/1488\/revisions\/1555"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/media\/1495"}],"wp:attachment":[{"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/media?parent=1488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/categories?post=1488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.montclair.edu\/phish-files\/wp-json\/wp\/v2\/tags?post=1488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}