A phishing email is currently being circulated among faculty, staff, and students. The email, titled "Notification of Student/Staffs Account Deactivation", claims to be from YorkU IT Admin and prompts recipients to submit personal information to prevent account deactivation.
Key details of the phishing email:
- From: York U IT Admin <jana.jakesova@KCHMPPCZ.onmicrosoft.com>
- Subject: Notification of Student/Staffs Account Deactivation
- Sent: October 14, 2024, 5:12 AM
The email falsely states that your York account will be disabled on October 16, 2024 unless you provide sensitive information, including your username, password, Duo/MFA passcodes, and personal contact information via a fraudulent email address.
Red Flags to Watch Out For:
- Suspicious sender email: The sender's email address [jana.jakesova@KCHMPPCZ.onmicrosoft.com] is not associated with York University’s official IT services.
- Urgency and fear tactics: The email pressures you to act immediately by threatening account deactivation.
- Request for personal details: York University would NEVER ask for passwords, Duo/MFA passcodes, or other sensitive information via email.
- Unsecure email address for responses: The email asks you to respond to a suspicious AOL email address (yorkuduosecuriity2024@aol.com), which is not a legitimate York University domain.
What to Do:
- Do not respond to this email or provide any personal information.
- Do not click any links or open attachments that may be included.
- Report the email: If you received this phishing attempt, please report it using the Report Phishing button or forward it to phishing@yorku.ca