{"id":3859,"date":"2026-05-11T09:46:50","date_gmt":"2026-05-11T07:46:50","guid":{"rendered":"https:\/\/blogs.ethz.ch\/its\/?p=3859"},"modified":"2026-05-11T09:46:52","modified_gmt":"2026-05-11T07:46:52","slug":"warning-fake-faculty-update-phishing-scam","status":"publish","type":"post","link":"https:\/\/blogs.ethz.ch\/its\/2026\/05\/11\/warning-fake-faculty-update-phishing-scam\/","title":{"rendered":"Warning: Fake &#171;Faculty Update&#187; Phishing Scam"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A sophisticated phishing email disguised as an internal ETH Zurich Faculty Update is currently circulating. Learn how to spot the warning signs and protect your credentials.<\/p>\n\n\n\n<figure class=\"wp-block-image size-post-size\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"335\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-600x335.jpg\" alt=\"phishing emails\" class=\"wp-image-3862\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-600x335.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-300x168.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-1024x572.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-768x429.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002-1536x858.jpg 1536w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/ID-CxS-News-Phishing-002.jpg 1920w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/figure>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">Call to Action<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you receive this email, do not click any links or enter your details; please delete it immediately. If you have already clicked the link and entered your credentials, please change your password immediately and contact the ITS Service Desk!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have received reports of a highly deceptive phishing email attempting to steal login credentials. The email appears to be an automated notification from SharePoint Online, claiming that an unknown user (such as &#171;Halea Beasley&#187;) has shared a document titled &#171;ETH Zurich Faculty Update&#187; with you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you click the link and attempt to log in, your credentials will be compromised. One user reported that after entering their details, they were simply redirected to a Microsoft Copilot page, a clever tactic used to mask the theft of their login information.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-2-002.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"742\" height=\"930\" data-id=\"3865\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-2-002.jpg\" alt=\"\" class=\"wp-image-3865\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-2-002.jpg 742w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-2-002-239x300.jpg 239w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-2-002-600x752.jpg 600w\" sizes=\"auto, (max-width: 742px) 100vw, 742px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"837\" data-id=\"3866\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002-1024x837.jpg\" alt=\"\" class=\"wp-image-3866\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002-1024x837.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002-300x245.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002-768x628.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002-600x490.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-3-002.jpg 1440w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"850\" data-id=\"3864\" src=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002-1024x850.jpg\" alt=\"\" class=\"wp-image-3864\" srcset=\"https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002-1024x850.jpg 1024w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002-300x249.jpg 300w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002-768x638.jpg 768w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002-600x498.jpg 600w, https:\/\/blogs.ethz.ch\/its\/files\/2026\/05\/CxS-Info-Hub-Phishing-1-002.jpg 1493w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Please remain vigilant and employ these essential checks before interacting with any unexpected file-sharing emails:<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Verify the sender&#8217;s identity<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do you actually know the person sharing the file? If the name is unfamiliar to you, treat the email with extreme caution.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Inspect the true email address<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Hover your mouse cursor over the sender&#8217;s name. In this specific phishing attempt, hovering reveals an external, unrecognised address (such as&nbsp;@wcsmail.org), rather than an official ETH Zurich account.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hover before you click<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Always hover your mouse over the document link or the &#171;Open&#187; button&nbsp;without clicking. This will display the actual destination URL. For this scam, the pop-up clearly shows the link directs to an external, suspicious domain (e.g.,&nbsp;wilkesk12ncus-my.sharepoint.com).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Read the fine print<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Check the footer of the email. This particular phishing message states it was generated through a completely unrelated organisation (wilkes.k12.nc.us).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to report an incident<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ethz.ch\/staffnet\/en\/it-services\/it-security\/awareness\/reporting-incidents.html\" target=\"_blank\" rel=\"noreferrer noopener\">Reporting cyber attacks &amp; incidents<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated phishing email disguised as an internal ETH Zurich Faculty Update is currently circulating. <\/p>\n","protected":false},"author":838,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257891,25],"tags":[301980,302023,302022,302024],"class_list":["post-3859","post","type-post","status-publish","format-standard","hentry","category-it-sec","category-news","tag-cyber-attacks","tag-phishing-email","tag-phishing-scam","tag-reporting-incidents"],"_links":{"self":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3859","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/users\/838"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/comments?post=3859"}],"version-history":[{"count":5,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3859\/revisions"}],"predecessor-version":[{"id":3868,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/posts\/3859\/revisions\/3868"}],"wp:attachment":[{"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/media?parent=3859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/categories?post=3859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.ethz.ch\/its\/wp-json\/wp\/v2\/tags?post=3859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}