Phishing Alert
A Cautionary Tale from Your Digital Voyage
Hark, travelers of the UMBC network!
The Cybersecurity Assurance and Digital Trust Department (CADT) has consulted the Oracle, and troubling omens appear on the horizon. A new set of treacherous phishing campaigns now circles our shores, and we need the wisdom of Odysseus and the courage of his crew to navigate safely home.
Beware These Perils:
🚩 The Sirens of False Support — Deceptive calls and messages claiming to hail from Microsoft Teams, ScreenConnect, or other IT services. Like the Sirens who lured sailors to their doom, these messages urge you to surrender your credentials or install unknown software with false urgency. Do not let their song enchant you.
🚩 The Trojan Invitations — Fraudulent meeting invites, event announcements, and resource links that appear legitimate but arrive from spoofed addresses. These gifts conceal malicious payloads within, just as the Greeks concealed warriors in their wooden horse.
🚩 The False Heralds of Banking — Counterfeit alerts mimicking banks and other financial institutions, demanding you "verify" your account through suspicious portals. True banks, like true allies, will never redirect you through treacherous links — they contact you through established channels they control.
Your Quest for Safety:
✅ Trust Your Oracle's Judgment. If an email stirs unease in your spirit, it likely harbors danger. Resist the urge to click — instead, navigate directly to official websites by entering the address yourself in the browser (for example: my.umbc.edu), not via email.
✅ Seek Verification Before Venturing Further. When messages claiming to be from DoIT demand swift action, do not follow the bait. Contact DoIT directly through channels you know to be true at security@umbc.edu.
✅ Be Wary of Manufactured Urgency. Attackers, like Circe, use haste and pressure to cloud your judgment. Pause. Reflect. Then decide.
✅ Never Paste Commands into Your Terminal or Run Prompt. Even if someone claims it to be a swift remedy or system update, this is how the most insidious attacks slip past your defenses. A single malicious command can compromise your entire vessel. If you are ever unsure, always verify directly with DoIT first.
✅ If You've Already Fallen into the Trap: Do not despair — swift action is your salvation. Change your myUMBC password immediately to something long and complex. Reject any DUO push notifications you did not initiate.
When Lost at Sea:
Reach out to us directly at security@umbc.edu — we are your guides through these digital straits. Every member of the UMBC community has the wisdom to stay vigilant; today, let that wisdom be your shield.
Thank you for your unwavering awareness and steadfast assistance in safeguarding our community's journey!
Cybersecurity Assurance and Digital Trust
UMBC Division of Information Technology (DoIT)