A confirmed phish email, appearing to be sent from a user's own spoofed York email address, with subject line "MAIL DNS (22) Undelivered Messages. Please check Domain settings!" was reported. Clicking on the link will redirect users to an external site: https://storage[.]cloud.google[.]com/maintainancecomponeta[.]appspot[.]com/myautoindex[.]html#username@yorku.ca If you clicked on the link and provided your credentials, please consider your […]
Advisories & Alerts
Phish Alert - Updated MAY Payment Structure And Classified Comapny Docments For You!!!
A phish email with subject line "Updated MAY Payment Structure And Classified Comapny Docments For You!!!" was sent to multiple mailboxes. Clicking on the link will redirect users to an external site:https://codee-1-a153d6.ingress-daribow[.]easywp.com/sv/#username@yorku.ca If you clicked on the link and provided your credentials, please consider your account as compromised. Change your password immediately and NEVER authorize […]
Phish Alert - Incoming Mail Delayed.
A confirmed phish email sent from a spoofed York email address, with subject line "Incoming Mail Delayed." was reported. Clicking on the link "Click here to retrieve your emails and reconfigure Port 486." will redirect users to an external site: https://firebasestorage[.]googleapis[.]com/v0/b/jiklo-102a6.appspot[.]com/o/1998228299llllllll%2Fwebwebweb.html?alt=media&token=9125baf0-abd4-4b12-8e44-acbfcb3d395c#username@yorku.ca If you clicked on the link and provided your credentials, please consider your account […]
Advisory Notice - OFAC sanctions and service restrictions
University Information Technology (UIT) is advising of current and upcoming changes to York-provided services Zoom and Duo (two-factor authentication) as a result of the situation in Ukraine. These services are now or will be unavailable to individuals attempting to authenticate from several countries and regions restricted by the Office of Foreign Assets Control (OFAC) — a financial intelligence […]
Phish Alert - April/May Salary updates
A confirmed phish email with subject line "April/May Salary updates" was reported. If you clicked on the link and provided your credentials, please consider your account as compromised. Change your password immediately and NEVER authorize a 2FA request that you did not initiate.
Cyber Security Advisory - Protecting against increased cyber threats
Russia’s invasion of Ukraine has resulted in an increase in global cyber threats. While there is no specific threat to York University, we would like to stress the importance of protecting your accounts, devices, and data. Protective steps include: Use multi-factor authentication with your accounts to help verify access. York’s Duo 2FA service is required […]
Phish Alert - (6) messages are pending yorku.ca
A phish email with subject line "(6) messages are pending yorku.ca" was sent to multiple mailboxes. Clicking on the link "RE-ACTIVATE ACCOUNT HERE" will redirect users to an external site: https://tummify.com/wp_locks/MailUpdateFresh#username@yorku.ca If you clicked on the link and provided your credentials, please consider your account as compromised. Change your password immediately and NEVER authorize […]
Phish Alert - Authorization Form
A sophisticated phish scam with subject line "Authorization Form" was sent to multiple mailboxes. The email has the attachment "yorku.ca Please_DocuSign_credit_card_Authorization.html" Opening the attachment will prompt the user to enter a password. You won't be able to change the username. If you click on Login, you will get the message "Invalid Password..! Please enter correct […]
Phish Alert - Updated JANUARY Payment Structure (Final Post-Covid-19 listing) !!!
A phishing email with subject line "Updated JANUARY Payment Structure (Final Post-Covid-19 listing) !!!" was sent to various mailboxes. Clicking on the xls link will redirect users to a fraudulent site http://managecld.com/log-in/ If you clicked on the link and provided your password, please consider your account as compromised. Change your password immediately and NEVER authorize […]
Job scam Alert - Bitcoin ATM Survey
Information Security has identified a job scam that advertises a phoney bitcoin job opportunity and encourages recipients to respond to an external email address. If you replied to the message, please: DO NOT REPLY TO ANY FURTHER MESSAGES RELATED TO THE SCAM Use the REPORT PHISHING button to report any additional messages related to the […]