[{"id":3408,"date":"2026-08-03T19:46:13","date_gmt":"2026-08-03T19:46:13","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3408"},"modified":"2026-08-03T19:46:51","modified_gmt":"2026-08-03T19:46:51","slug":"phishing-alert-fake-google-account-verification-emails-targeting-vcu-accounts-with-malicious-google-form-link","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/08\/03\/phishing-alert-fake-google-account-verification-emails-targeting-vcu-accounts-with-malicious-google-form-link\/","title":{"rendered":"Phishing Alert: Fake &#8220;Google Account Verification&#8221; Emails Targeting VCU Accounts with Malicious Google Form Link (8\/3\/2026)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We are currently seeing a wave of phishing emails sent from <strong>compromised VCU accounts<\/strong>. These messages claim your account will be suspended or deleted unless you &#8220;verify&#8221; it through a Google Form link. <strong>This is a scam \u2014 do not click the link or enter any information.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What the email looks like:<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Dear User,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are unable to process incoming emails to your school account because your Google account verification has failed. If this issue is not resolved within the next few hours, your account may be permanently deleted from our system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please take immediate action to verify your account to avoid any disruption.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally, alumni and former students are also required to complete the verification process using the link provided.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To avoid losing access, please verify your account immediately by clicking the link: [MALICIOUS LINK]. Failure to do so may result in permanent loss of access to your account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the link is not working, copy and paste the URL below into the address bar of your web browser to cancel the request: [MALICIOUS LINK]<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note: On the form, there&#8217;s a field labeled &#8220;ACP.&#8221; This actually means your email password \u2014 the one you use to log in to your email account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please answer all your questions. If you do not have an answer to a particular question, write &#8216;Nil&#8217;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thank you for your prompt attention to this matter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sincerely,<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to spot it:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Urgent, threatening language about account deletion or lost access<\/li>\n\n\n\n<li>A generic greeting (&#8220;Dear User&#8221;) instead of your name<\/li>\n\n\n\n<li>A request to fill out a Google Form with personal account details<\/li>\n\n\n\n<li>Any field asking for your password \u2014 VCU and Google will <strong>never<\/strong> ask for your password through a form<\/li>\n\n\n\n<li>Coming from a real (but compromised) VCU email address, which can make it look more legitimate than a typical phishing attempt<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What to do:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Do not click the link.<\/strong> If you already did, do not enter any information.<\/li>\n\n\n\n<li><strong>Do not enter your password, ACP, or any account credentials into the form<\/strong>, no matter how the field is labeled.<\/li>\n\n\n\n<li><strong>If you already submitted information<\/strong>, change your password immediately and contact us right away.<\/li>\n\n\n\n<li><strong>Report suspicious emails<\/strong> by forwarding them to <a href=\"mailto:phishing@vcu.edu\">phishing@vcu.edu<\/a>.<\/li>\n\n\n\n<li><strong>Questions or concerns?<\/strong> Reach out to <a href=\"mailto:infosec@vcu.edu\">infosec@vcu.edu<\/a>.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you receive this email from someone you know, assume their account has been compromised \u2014 do not reply to it and report it to us<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are currently seeing a wave of phishing emails sent from compromised VCU accounts. These messages claim your account will be suspended or deleted unless you &#8220;verify&#8221; it through a Google Form link. This is a scam \u2014 do not click the link or enter any information. What the email looks like: Dear User, We [&hellip;]<\/p>\n","protected":false},"author":927,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3408","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/927"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3408"}],"version-history":[{"count":2,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3408\/revisions"}],"predecessor-version":[{"id":3410,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3408\/revisions\/3410"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3404,"date":"2026-07-28T10:14:42","date_gmt":"2026-07-28T10:14:42","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3404"},"modified":"2026-07-28T10:14:43","modified_gmt":"2026-07-28T10:14:43","slug":"more-fake-it-text-messages-targeting-vcu-users-7-28-2026","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/07\/28\/more-fake-it-text-messages-targeting-vcu-users-7-28-2026\/","title":{"rendered":"More Fake IT Text Messages Targeting VCU Users (7\/28\/2026)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">There is a another phisher with the phone number (<strong><span style=\"text-decoration: underline\">1-202-300-0772)<\/span><\/strong> that is texting users and threatening to shut down user&#8217;s email accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We&#8217;ve seen this attack previously (<a href=\"https:\/\/blogs.vcu.edu\/phishing\/2026\/06\/25\/fake-it-text-messages-targeting-vcu-users-6-25-2026\/\">https:\/\/blogs.vcu.edu\/phishing\/2026\/06\/25\/fake-it-text-messages-targeting-vcu-users-6-25-2026\/<\/a>)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please be <strong><span style=\"text-decoration: underline\">aware<\/span><\/strong> this is a <strong><span style=\"text-decoration: underline\">scam<\/span><\/strong>. If you responded to the text message and provided your user\/password, please contact us at phishing@vcu.edu and following these instructions to reset your password: <a href=\"https:\/\/knowledgebase.vcu.edu\/portal\/app\/portlets\/results\/viewsolution.jsp?solutionid=240503162018383\">https:\/\/knowledgebase.vcu.edu\/portal\/app\/portlets\/results\/viewsolution.jsp?solutionid=240503162018383<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"472\" height=\"1024\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-472x1024.png\" alt=\"\" class=\"wp-image-3405\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-472x1024.png 472w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-138x300.png 138w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-768x1665.png 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-709x1536.png 709w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-945x2048.png 945w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/07\/IMG_2433-redacted-scaled.png 1181w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>There is a another phisher with the phone number (1-202-300-0772) that is texting users and threatening to shut down user&#8217;s email accounts. We&#8217;ve seen this attack previously (https:\/\/blogs.vcu.edu\/phishing\/2026\/06\/25\/fake-it-text-messages-targeting-vcu-users-6-25-2026\/) Please be aware this is a scam. If you responded to the text message and provided your user\/password, please contact us at phishing@vcu.edu and following these instructions [&hellip;]<\/p>\n","protected":false},"author":894,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3404","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/894"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3404"}],"version-history":[{"count":1,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3404\/revisions"}],"predecessor-version":[{"id":3406,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3404\/revisions\/3406"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3400,"date":"2026-06-25T13:52:58","date_gmt":"2026-06-25T13:52:58","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3400"},"modified":"2026-06-25T13:53:00","modified_gmt":"2026-06-25T13:53:00","slug":"fake-it-text-messages-targeting-vcu-users-6-25-2026","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/06\/25\/fake-it-text-messages-targeting-vcu-users-6-25-2026\/","title":{"rendered":"Fake IT Text Messages Targeting VCU Users 6\/25\/2026"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">There is a phisher with the phone number (1-680-223-5968) that is texting users and threatening to shut down user&#8217;s email accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please be aware this is a scam.  If you responded to the text message and provided your user\/password, please contact us at phishing@vcu.edu and following these instructions to reset your password: <a href=\"https:\/\/knowledgebase.vcu.edu\/portal\/app\/portlets\/results\/viewsolution.jsp?solutionid=240503162018383\">https:\/\/knowledgebase.vcu.edu\/portal\/app\/portlets\/results\/viewsolution.jsp?solutionid=240503162018383<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"456\" height=\"1024\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-456x1024.png\" alt=\"\" class=\"wp-image-3401\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-456x1024.png 456w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-134x300.png 134w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-768x1724.png 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-684x1536.png 684w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text-912x2048.png 912w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/06\/threatening_text.png 1080w\" sizes=\"auto, (max-width: 456px) 100vw, 456px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>There is a phisher with the phone number (1-680-223-5968) that is texting users and threatening to shut down user&#8217;s email accounts. Please be aware this is a scam. If you responded to the text message and provided your user\/password, please contact us at phishing@vcu.edu and following these instructions to reset your password: https:\/\/knowledgebase.vcu.edu\/portal\/app\/portlets\/results\/viewsolution.jsp?solutionid=240503162018383<\/p>\n","protected":false},"author":894,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3400","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/894"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3400"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3400\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3396,"date":"2026-04-06T14:29:52","date_gmt":"2026-04-06T14:29:52","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3396"},"modified":"2026-04-06T14:29:53","modified_gmt":"2026-04-06T14:29:53","slug":"fake-invitation-malware-4-6-26","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/04\/06\/fake-invitation-malware-4-6-26\/","title":{"rendered":"Fake Invitation MALWARE! 4\/6\/26"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The &#8220;Dinner Party&#8221; Phishing Scam: Don&#8217;t RSVP to Danger<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The latest phishing attempt hitting VCU inboxes is a masterclass in subtlety. Instead of scary threats about account deactivation, this one uses <strong>social engineering<\/strong> to pique your curiosity with a sophisticated-looking &#8220;Dinner Party&#8221; invitation. We have seen repeated use of this <strong>Greenvelope<\/strong> tool being used to spread malware, once you click the link a download can trigger. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use your mouse to hover over a link in an email and beware sites that end with &#8220;.de&#8221;.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"351\" height=\"35\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101441.png\" alt=\"\" class=\"wp-image-3398\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101441.png 351w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101441-300x30.png 300w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"692\" height=\"541\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101405.png\" alt=\"\" class=\"wp-image-3397\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101405.png 692w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/Screenshot-2026-04-06-101405-300x235.png 300w\" sizes=\"auto, (max-width: 692px) 100vw, 692px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Anatomy of the Scam<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The email appears to be an elegant digital invitation from <strong>Greenvelope<\/strong>, a legitimate e-invitation service. It looks professional, clean, and features an aesthetic floral design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The hook is simple:<\/strong> Curiosity. You receive an invitation for a &#8220;Dinner Party&#8221; with no sender name clearly visible in the graphic, tempting you to click the <strong>&#8220;Invitation&#8221;<\/strong> or <strong>&#8220;RSVP&#8221;<\/strong> links to see who is hosting.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why This is Dangerous<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This &#8220;soft&#8221; approach is often more effective than aggressive scams because it doesn&#8217;t raise immediate red flags. Here is why it&#8217;s high-level:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Platform Spoofing:<\/strong> By using the branding of a real service like Greenvelope, the attackers bypass your initial &#8220;scam radar.&#8221;<\/li>\n\n\n\n<li><strong>Targeted Curiosity:<\/strong> Humans are naturally curious. If you think you might have been invited to an exclusive departmental dinner or a student gala, you&#8217;re more likely to click.<\/li>\n\n\n\n<li><strong>The Payload:<\/strong> Clicking the link doesn&#8217;t take you to a guest list. Instead, it likely leads to a <strong>spoofed VCU login page<\/strong> or a site designed to drop <strong>malware<\/strong> onto your device.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">What to Do<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Do Not Click:<\/strong> Clicking the link confirms to the attacker that your email is active and you are &#8220;click-prone.&#8221;<\/li>\n\n\n\n<li><strong>Report the Invite:<\/strong> Even if it looks pretty, it&#8217;s still poison. Forward the email to <strong>phishing@vcu.edu<\/strong> immediately.<\/li>\n\n\n\n<li><strong>Warn Your Peers:<\/strong> If you see classmates talking about a &#8220;mysterious dinner invite,&#8221; let them know it\u2019s a confirmed phishing attempt.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Remember:<\/strong> If an invitation to a fancy party arrives out of the blue, it\u2019s likely not a seat at the table\u2014it\u2019s an attempt to steal your seat at VCU.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stay safe and stay skeptical!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;Dinner Party&#8221; Phishing Scam: Don&#8217;t RSVP to Danger The latest phishing attempt hitting VCU inboxes is a masterclass in subtlety. Instead of scary threats about account deactivation, this one uses social engineering to pique your curiosity with a sophisticated-looking &#8220;Dinner Party&#8221; invitation. We have seen repeated use of this Greenvelope tool being used to [&hellip;]<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3396","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3396"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3396\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3394,"date":"2026-04-03T17:42:34","date_gmt":"2026-04-03T17:42:34","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3394"},"modified":"2026-04-03T17:57:48","modified_gmt":"2026-04-03T17:57:48","slug":"urgent-job-scam-alert-vacancy-announcement-administrative-assistant-part-time","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/04\/03\/urgent-job-scam-alert-vacancy-announcement-administrative-assistant-part-time\/","title":{"rendered":"URGENT: [Job Scam Alert] Vacancy Announcement: Administrative Assistant (Part-Time)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Other Subject Lines: <strong>WORK AND STUDY PART-TIME<\/strong> &amp; <strong>Virginia Commonwealth University Act Now<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Information Security office is aware of a <strong>job scam<\/strong>&nbsp;which originated from the email&nbsp;<strong>&#8216;gabrielsanchez712396@gmail[.]com&#8217;&nbsp;<\/strong>The scammer compromised a number of VCU email accounts and used them to further the scam. This was done so that it appeared legitimate, as the scam was now coming from&nbsp;@<a href=\"http:\/\/vcu.edu\/\" target=\"_blank\" rel=\"noreferrer noopener\">vcu.edu<\/a>&nbsp;email addresses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please <strong>stop all communications&nbsp;<\/strong>with the&nbsp;job scammer<strong>&nbsp;immediately.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Additionally<strong>&nbsp;do not&nbsp;<\/strong>deposit any checks&nbsp;or&nbsp;send the scammer any money, gift-cards, cash app or other forms of payments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you shared any information with the scammer such as phone number or address, they may attempt to contact you with other&nbsp;job scams. If you receive any odd or suspicious emails or job scam texts,&nbsp;please&nbsp;report those emails or texts to&nbsp;<a href=\"mailto:phishing@vcu.edu\" target=\"_blank\" rel=\"noreferrer noopener\">phishing@vcu.edu<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">VCU will never ask for your password or ask you to validate your credentials to continue using our email system. VCU will never offer you a job in which you did not apply for.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>If you did not click on the google form, submit your credentials, or communicate with the scammer then there is no action needed on your end.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Other Subject Lines: WORK AND STUDY PART-TIME &amp; Virginia Commonwealth University Act Now The Information Security office is aware of a job scam&nbsp;which originated from the email&nbsp;&#8216;gabrielsanchez712396@gmail[.]com&#8217;&nbsp;The scammer compromised a number of VCU email accounts and used them to further the scam. This was done so that it appeared legitimate, as the scam was now [&hellip;]<\/p>\n","protected":false},"author":927,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3394","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/927"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3394"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3394\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3390,"date":"2026-04-01T15:39:16","date_gmt":"2026-04-01T15:39:16","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3390"},"modified":"2026-04-01T15:39:17","modified_gmt":"2026-04-01T15:39:17","slug":"fake-text-from-it-vcu-it-will-never-text-you","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/04\/01\/fake-text-from-it-vcu-it-will-never-text-you\/","title":{"rendered":"Fake Text From IT&#8230;VCU IT Will Never Text You!"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">We are issuing a formal warning regarding a fraudulent messaging campaign currently targeting Virginia Commonwealth University students and faculty.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The scam involves a text message or email claiming to be from the <strong>&#8220;Microsoft IT Help Department.&#8221;<\/strong> The message falsely alleges that a request has been initiated to deactivate your official VCU email account and prompts you to respond or click a link to cancel the action.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"473\" height=\"1024\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-473x1024.png\" alt=\"\" class=\"wp-image-3392\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-473x1024.png 473w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-139x300.png 139w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-768x1663.png 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-709x1536.png 709w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1-946x2048.png 946w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/04\/IMG_5077-1.png 960w\" sizes=\"auto, (max-width: 473px) 100vw, 473px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Key Indicators of Fraud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To help you identify this and future threats, please note the following red flags:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>External Origin:<\/strong> Official VCU account notifications are never sent via SMS from personal or unverified mobile numbers.<\/li>\n\n\n\n<li><strong>Misleading Branding:<\/strong> The message uses &#8220;Microsoft IT&#8221; to gain trust, rather than <strong>VCU Technology Services<\/strong>, which manages our institutional accounts.<\/li>\n\n\n\n<li><strong>Sense of Urgency:<\/strong> The threat of immediate account deactivation is a common social engineering tactic used to bypass critical thinking and provoke a fast response.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended Action Plan<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you receive this message or any communication that feels suspicious, please adhere to the following security protocols:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Do Not Engage:<\/strong> Do not reply to the sender or click on any provided links.<\/li>\n\n\n\n<li><strong>Protect Your Credentials:<\/strong> VCU will never ask for your password or Duo authentication codes via text or unsolicited email.<\/li>\n\n\n\n<li><strong>Report the Incident:<\/strong> Please forward any suspicious emails or screenshots of text messages to <strong>phishing@vcu.edu<\/strong>. Reporting these incidents allows the Information Security team to block malicious senders and protect the wider VCU community.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If you have already interacted with the message or provided your credentials, please change your VCU eID password immediately and contact <strong>phishing@vcu.edu<\/strong> or the <strong>IT Support Center at (804) 828-2227<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The information security office has now activated our<strong> phishing@vcu.edu<\/strong> inbox to be the official inbox users should report suspicious emails to. Please assist us in spreading the word that our office would now prefer the VCU Community to report suspicious emails to <strong>phishing@vcu.edu<\/strong> instead of <strong>infosec@vcu.edu<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are issuing a formal warning regarding a fraudulent messaging campaign currently targeting Virginia Commonwealth University students and faculty. The scam involves a text message or email claiming to be from the &#8220;Microsoft IT Help Department.&#8221; The message falsely alleges that a request has been initiated to deactivate your official VCU email account and prompts [&hellip;]<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3390","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3390"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3390\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3388,"date":"2026-02-06T17:32:11","date_gmt":"2026-02-06T17:32:11","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3388"},"modified":"2026-02-06T17:32:12","modified_gmt":"2026-02-06T17:32:12","slug":"new-phishing-alert-fake-vcu-two%e2%80%91factor-enrollment-email","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/02\/06\/new-phishing-alert-fake-vcu-two%e2%80%91factor-enrollment-email\/","title":{"rendered":"New Phishing Alert: Fake VCU Two\u2011Factor Enrollment Email"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A new phishing email is circulating through our community, and this one is crafted to look highly official. Attackers are attempting to steal user credentials by imitating a \u201cVCU Two\u2011Factor enrollment update,\u201d complete with university branding and a QR code that leads to a malicious website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">VCU will NEVER ask for your personal data with a QR code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">QR codes are dominating the hacker scene right now please NEVER scan a qr code or click a link from an email you don&#8217;t recognize. Try googling more about the request first in a seperate tab. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"642\" height=\"642\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingpc3.png\" alt=\"\" class=\"wp-image-3389\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingpc3.png 642w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingpc3-300x300.png 300w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingpc3-150x150.png 150w\" sizes=\"auto, (max-width: 642px) 100vw, 642px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why This Scam Is Dangerous<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Scanning the QR code or clicking any links may send you to a fake login portal designed to capture:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your VCU eID and password<\/li>\n\n\n\n<li>MFA codes<\/li>\n\n\n\n<li>Additional personal information<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Once an attacker gains access to your account, they can attempt further compromises, send additional phishing messages, and potentially access protected data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How to Spot This Scam<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Look for these warning signs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Unexpected requests to \u201cenroll,\u201d \u201cre-enroll,\u201d or \u201cupdate\u201d MFA<\/li>\n\n\n\n<li>Messages delivered late at night or from unfamiliar names<\/li>\n\n\n\n<li>QR codes in unsolicited emails<\/li>\n\n\n\n<li>Urgent or authoritative language pressuring quick action<\/li>\n\n\n\n<li>Slightly altered sender addresses or formatting inconsistencies<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you did not request an MFA update, you should never receive one without official notice from VCU Technology Services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What To Do If You Receive This Email<\/strong><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Do not scan the QR code.<\/strong><\/li>\n\n\n\n<li><strong>Do not click any links.<\/strong><\/li>\n\n\n\n<li><strong>Report the message immediately<\/strong> by forwarding it to your security\/IT contact or using the \u201cReport Phishing\u201d button.<\/li>\n\n\n\n<li><strong>Delete the email<\/strong> from your inbox.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>If You Already Interacted With the Email<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you scanned the code or entered any information:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Change your VCU password immediately<\/strong><\/li>\n\n\n\n<li><strong>Notify Information Security right away<\/strong><\/li>\n\n\n\n<li><strong>Monitor your account for unusual activity<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new phishing email is circulating through our community, and this one is crafted to look highly official. Attackers are attempting to steal user credentials by imitating a \u201cVCU Two\u2011Factor enrollment update,\u201d complete with university branding and a QR code that leads to a malicious website. VCU will NEVER ask for your personal data with [&hellip;]<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3388","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3388"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3388\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3386,"date":"2026-02-05T16:49:43","date_gmt":"2026-02-05T16:49:43","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3386"},"modified":"2026-02-05T16:49:45","modified_gmt":"2026-02-05T16:49:45","slug":"invitation-to-party-scam","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2026\/02\/05\/invitation-to-party-scam\/","title":{"rendered":"Invitation to party? SCAM"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A new phishing campaign is making the rounds on campus, and it\u2019s disguised as something friendly and harmless: a party invitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recently, members of our community received an email claiming <strong>\u201cYou\u2019re invited to my private party,\u201d<\/strong> complete with what looks like an e\u2011card and a link to \u201cdownload the card.\u201d While it may appear like a simple digital invitation, this message is <strong>a malicious phishing attempt designed to trick recipients into downloading harmful content or entering personal information.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"951\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2-1024x951.jpg\" alt=\"\" class=\"wp-image-3387\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2-1024x951.jpg 1024w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2-300x279.jpg 300w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2-768x713.jpg 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2-1536x1427.jpg 1536w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2026\/02\/phishingexample2.jpg 1700w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s what you need to know to stay safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Red Flags to Spot Immediately<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This scam is subtle, but several features should raise suspicion:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Generic, vague messaging<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There is no event name, no sender context, and no personal detail\u2014hallmarks of mass\u2011sent phishing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Unexpected attachments or downloads<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Legitimate invitation platforms do not require you to download a file to view an invite.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Inconsistent formatting<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The email shown has large blank areas, odd alignment, and mismatched fonts\u2014common signs of a hastily constructed phishing template.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. External, unverified email sender<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The message originates from an unknown external address pretending to represent a known service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>If You Receive an Email Like This<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s what to do:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Do NOT click any links or download attachments.<\/strong><\/li>\n\n\n\n<li><strong>Report the message<\/strong> to the VCU Information Security Office.<\/li>\n\n\n\n<li><strong>Delete the email<\/strong> from your inbox and trash.<\/li>\n\n\n\n<li>If you accidentally clicked the link or entered your login information:\n<ul class=\"wp-block-list\">\n<li>Change your password immediately.<\/li>\n\n\n\n<li>Contact your IT security team for assistance.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stay safe online and remember to do your annual security training!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new phishing campaign is making the rounds on campus, and it\u2019s disguised as something friendly and harmless: a party invitation. Recently, members of our community received an email claiming \u201cYou\u2019re invited to my private party,\u201d complete with what looks like an e\u2011card and a link to \u201cdownload the card.\u201d While it may appear like [&hellip;]<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3386","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3386"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3386\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3382,"date":"2025-12-11T20:59:59","date_gmt":"2025-12-11T20:59:59","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3382"},"modified":"2025-12-11T21:01:49","modified_gmt":"2025-12-11T21:01:49","slug":"text-from-dr-rao-12-11-25","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2025\/12\/11\/text-from-dr-rao-12-11-25\/","title":{"rendered":"Text from Dr. Rao 12\/11\/25"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Please beware of a text scam impersonating Dr. Rao asking for help with a quick task. If you received this it is a scam please do not respond to the scammer. See example of the scam below. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please report to infosec@vcu.edu, if you have further questions or comments. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"472\" height=\"1024\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-472x1024.png\" alt=\"\" class=\"wp-image-3383\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-472x1024.png 472w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-138x300.png 138w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-768x1665.png 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-709x1536.png 709w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5-945x2048.png 945w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/12\/unnamed-5.png 1179w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Please beware of a text scam impersonating Dr. Rao asking for help with a quick task. If you received this it is a scam please do not respond to the scammer. See example of the scam below. Please report to infosec@vcu.edu, if you have further questions or comments.<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3382","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3382"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3382\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}},{"id":3378,"date":"2025-08-14T23:17:25","date_gmt":"2025-08-14T23:17:25","guid":{"rendered":"https:\/\/blogs.vcu.edu\/phishing\/?p=3378"},"modified":"2025-08-14T23:17:27","modified_gmt":"2025-08-14T23:17:27","slug":"fake-vcu-login-page-linked-in-phishing-email","status":"publish","type":"post","link":"https:\/\/blogs.vcu.edu\/phishing\/2025\/08\/14\/fake-vcu-login-page-linked-in-phishing-email\/","title":{"rendered":"FAKE VCU Login Page linked in Phishing Email"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello please beware a phishing email matching the description below this phishing email contains a fake webpage to capture your username and password. Please reset your password if you have clicked the link. <\/p>\n\n\n\n\n\n\n\n\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"472\" height=\"1024\" src=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-472x1024.png\" alt=\"\" class=\"wp-image-3379\" srcset=\"https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-472x1024.png 472w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-138x300.png 138w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-768x1665.png 768w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-709x1536.png 709w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943-945x2048.png 945w, https:\/\/blogs.vcu.edu\/phishing\/wp-content\/uploads\/sites\/565\/2025\/08\/IMG_8943.png 1179w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Hello please beware a phishing email matching the description below this phishing email contains a fake webpage to capture your username and password. Please reset your password if you have clicked the link.<\/p>\n","protected":false},"author":1597,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3378","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/users\/1597"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/comments?post=3378"}],"version-history":[{"count":0,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/posts\/3378\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/media?parent=3378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/categories?post=3378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.vcu.edu\/phishing\/wp-json\/wp\/v2\/tags?post=3378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}]