<?xml version="1.0"?>
<News hasArchived="false" page="1" pageCount="1" pageSize="10" timestamp="Fri, 09 Oct 2026 19:40:11 -0400" url="https://my3.my.umbc.edu/groups/itsecurity/posts.xml?tag=google-calendar">
<NewsItem contentIssues="false" id="163968" important="true" status="posted" url="https://my3.my.umbc.edu/groups/itsecurity/posts/163968">
<Title>URGENT: Recent Phishing Incident &amp; Heightened Awareness</Title>
<Tagline>Repost from the Maryland Department of Budget &amp; Management</Tagline>
<Body>
<![CDATA[
    <div class="html-content">
    <p><strong>Dear State Employees,</strong></p>
    <p>Multiple users within state agencies were recently targeted and impacted by a successful phishing attack. A phishing campaign has been observed compromising internal accounts via malicious Google calendar invites. </p>
    <p><strong>Employees should report suspicious messages and calendar invites immediately:</strong> Do not forward, reply to, or click links in a suspicious email and do not accept calendar invites that seem unusual. Use the <strong>"Report Phishing"</strong> button in your email client or contact the Maryland Security Operations Center (MD-SOC) at <a href="mailto:soc@maryland.gov" rel="nofollow external" class="bo">soc@maryland.gov</a> or through the cybersecurity incident reporting form at <a href="https://links-1.govdelivery.com/CL0/https:%2F%2Fdoit.maryland.gov%2Fcybersecurityincident/1/010001a11e93e89a-5953fb42-681a-4a9e-8175-04e1f6163469-000000/ISuLtXaY4iV-6mGiMWKhLpyeDtiJtOK8mrwRqH_P2ig=452" rel="nofollow external" class="bo">https://doit.maryland.gov/cybersecurityincident</a>. Prompt reporting allows our security team to block threats for all employees. If you believe that you have clicked on a malicious link, report it immediately to the MD-SOC. The MD-SOC operates 24x7. IT security incidents can be reported​ to <a href="mailto:soc@maryland.gov" rel="nofollow external" class="bo">soc@maryland.gov</a> via email or by calling <a rel="nofollow external" class="bo">410-697-9700</a>, option 5.</p>
    <p><strong>Phishing attacks</strong>—fraudulent emails designed to manipulate recipients into revealing sensitive information, clicking malicious links, or downloading harmful attachments—continue to be a leading tactic used by malicious actors.</p>
    <p>Please review the following red flags and best practices to keep our digital environment secure.</p>
    <h3><strong>How to Spot a Phishing Email</strong></h3>
    <p>Malicious actors often imitate leadership, state agencies, IT support, or familiar vendors. Watch out for these key indicators:</p>
    <ul>
    <li>
    <strong>Urgent or Threatening Language:</strong> Messages demanding immediate action (e.g., "Account suspended," "Immediate password reset required," or "Urgent wire transfer").</li>
    <li>
    <strong>Mismatched or Unfamiliar Sender Addresses:</strong> Look closely at the sender’s full email address, not just the display name. Check for slight misspellings or abnormal domain extensions like .org where you expect .gov.</li>
    <li>
    <strong>Suspicious Links &amp; Attachments:</strong> Hover your cursor over links (without clicking) to verify the destination web address. Be cautious of unexpected attachments, and verify them with the sender using an alternative medium to email such as a call to a known good number..</li>
    <li>
    <strong>Requests for Sensitive Information:</strong> IT will never ask for your password. Be wary of requests for other sensitive information such as your Social Security number or personal financial details via email, and verify such requests with the sender through an alternative medium.</li>
    </ul>
    <h3><strong>Core Best Practices for Cybersecurity</strong></h3>
    <p>Adopting a few daily security habits significantly reduces risk across all state operations:</p>
    <ol>
    <li>
    <strong>Verify Before You Act:</strong> If an email seems unusual or requests sensitive actions—even if it appears to come from a supervisor, frequent contact, or vendor—verify the request through a secondary, trusted communication channel (like a phone call or direct message). Malicious links and attachments can also come in the form of calendar invites, so be suspicious of any unexpected invites you receive or that appear on your calendar and verify them. Verify the legitimacy of any website that requests your username or password before entering them. Phishing is frequently used to gather credentials and gain access to accounts. Malicious actors can identify common web portals used by state employees and create convincing fakes, so a familiar website appearance does not guarantee the authenticity of the website. If you have any doubt about the authenticity of a website do not enter any information and contact the MD-SOC for help.</li>
    <li>
    <strong>Use Multi-Factor Authentication (MFA):</strong> Ensure MFA is enabled across all accessible state systems to prevent unauthorized access even if credentials are compromised.</li>
    <li>
    <strong>Practice Strong Password Hygiene:</strong> Never reuse passwords across work and personal accounts. Use long, unique passphrases.</li>
    <li>
    <strong>Report Suspicious Messages Immediately:</strong> Do not forward, reply to, or click links in a suspicious email. Use the <strong>"Report Phishing"</strong> button in your email client or contact the Maryland Security Operations Center (MD-SOC) at <a href="mailto:soc@maryland.gov" rel="nofollow external" class="bo">soc@maryland.gov</a> or through the cybersecurity incident reporting form at <a href="https://links-1.govdelivery.com/CL0/https:%2F%2Fdoit.maryland.gov%2Fcybersecurityincident/2/010001a11e93e89a-5953fb42-681a-4a9e-8175-04e1f6163469-000000/SNIw2Pl95Fl_OSPBFlEXECtEziryxBOQokX2JxMe2P8=452" rel="nofollow external" class="bo">https://doit.maryland.gov/cybersecurityincident</a>. Prompt reporting allows our security team to block threats for all employees.</li>
    </ol>
    <p>Thank you for your continued dedication to keeping our state network safe and resilient.</p>
    <p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~</p>
    <h3>Note from UMBC's Cybersecurity Assurance and Digital Trust Team: </h3>
    <p>If you suspect phishing, please contact us at <a href="mailto:security@umbc.edu/" rel="nofollow external" class="bo">security@umbc.edu/</a> </p>
    </div>
]]>
</Body>
<Summary>Dear State Employees,   Multiple users within state agencies were recently targeted and impacted by a successful phishing attack. A phishing campaign has been observed compromising internal...</Summary>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/163968/guest@my.umbc.edu/8f190355a7d7c1897381950e5d502992/api/pixel</TrackingUrl>
<Tag>alert</Tag>
<Tag>google-calendar</Tag>
<Tag>phishing</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="original">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/original.png?1761588639</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="large">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/large.png?1761588639</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/medium.png?1761588639</AvatarUrl>
<AvatarUrl size="small">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/small.png?1761588639</AvatarUrl>
<AvatarUrl size="xsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxsmall.png?1761588639</AvatarUrl>
<Sponsor>IT Security - DoIT Cybersecurity Assurance and Digital Trust</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Fri, 09 Oct 2026 10:11:55 -0400</PostedAt>
</NewsItem>

</News>
