Warning: Fake «Faculty Update» Phishing Scam

A sophisticated phishing email disguised as an internal ETH Zurich Faculty Update is currently circulating. Learn how to spot the warning signs and protect your credentials.

phishing emails

Call to Action

If you receive this email, do not click any links or enter your details; please delete it immediately. If you have already clicked the link and entered your credentials, please change your password immediately and contact the ITS Service Desk!

We have received reports of a highly deceptive phishing email attempting to steal login credentials. The email appears to be an automated notification from SharePoint Online, claiming that an unknown user (such as «Halea Beasley») has shared a document titled «ETH Zurich Faculty Update» with you.

If you click the link and attempt to log in, your credentials will be compromised. One user reported that after entering their details, they were simply redirected to a Microsoft Copilot page, a clever tactic used to mask the theft of their login information.

Please remain vigilant and employ these essential checks before interacting with any unexpected file-sharing emails:

Verify the sender’s identity

Do you actually know the person sharing the file? If the name is unfamiliar to you, treat the email with extreme caution.

Inspect the true email address

Hover your mouse cursor over the sender’s name. In this specific phishing attempt, hovering reveals an external, unrecognised address (such as @wcsmail.org), rather than an official ETH Zurich account.

Hover before you click

Always hover your mouse over the document link or the «Open» button without clicking. This will display the actual destination URL. For this scam, the pop-up clearly shows the link directs to an external, suspicious domain (e.g., wilkesk12ncus-my.sharepoint.com).

Read the fine print

Check the footer of the email. This particular phishing message states it was generated through a completely unrelated organisation (wilkes.k12.nc.us).

How to report an incident

Reporting cyber attacks & incidents

erstellt am
in IT-SEC,News Schlagwörter: ,,,

Hinterlassen Sie eine Antwort

Ihre E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

This site uses Akismet to reduce spam. Learn how your comment data is processed.