Warning: Fake «Faculty Update» Phishing Scam
A sophisticated phishing email disguised as an internal ETH Zurich Faculty Update is currently circulating. Learn how to spot the warning signs and protect your credentials.

Call to Action
If you receive this email, do not click any links or enter your details; please delete it immediately. If you have already clicked the link and entered your credentials, please change your password immediately and contact the ITS Service Desk!
We have received reports of a highly deceptive phishing email attempting to steal login credentials. The email appears to be an automated notification from SharePoint Online, claiming that an unknown user (such as «Halea Beasley») has shared a document titled «ETH Zurich Faculty Update» with you.
If you click the link and attempt to log in, your credentials will be compromised. One user reported that after entering their details, they were simply redirected to a Microsoft Copilot page, a clever tactic used to mask the theft of their login information.



Please remain vigilant and employ these essential checks before interacting with any unexpected file-sharing emails:
Verify the sender’s identity
Do you actually know the person sharing the file? If the name is unfamiliar to you, treat the email with extreme caution.
Inspect the true email address
Hover your mouse cursor over the sender’s name. In this specific phishing attempt, hovering reveals an external, unrecognised address (such as @wcsmail.org), rather than an official ETH Zurich account.
Hover before you click
Always hover your mouse over the document link or the «Open» button without clicking. This will display the actual destination URL. For this scam, the pop-up clearly shows the link directs to an external, suspicious domain (e.g., wilkesk12ncus-my.sharepoint.com).
Read the fine print
Check the footer of the email. This particular phishing message states it was generated through a completely unrelated organisation (wilkes.k12.nc.us).


