Trending phishing scams - party invitation and Microsoft 365 authentication phish

This message is intended for U-M IT staff who are responsible for IT security in units.

Summary

Two types of phishing scams have become increasingly prevalent recently: 

  • party invitation email that appears to be sent from someone known to the recipient (using a compromised account), leads the recipient to download and execute a malicious file.
  • Microsoft 365 authentication phish sent through email uses the pretense of accessing a document to get the user to respond to a prompt for Microsoft 365 login and submit a verification code. If the recipient submits the verification code, it grants the threat actor's device persistent access to the user's Microsoft 365 account.

Action Items

View the phishing alerts to learn more about recognizing and avoiding these scams, and share the information with your unit.

If users think they may have fallen for either of these phishing scams, i.e., downloaded and executed a malicious file or submitted a verification code, they should contact [email protected].

How We Protect U-M

ITS provides CrowdStrike Falcon to units, which should be installed on all U-M owned systems (Windows, macOS, and Linux operating systems, whether workstations or servers). Falcon administrators in ITS and in U-M units use the Falcon console to investigate and remediate issues.

Information for Users

In general, the best protection for your devices is this: keep your software and apps up-to-date, do not click suspicious links in email, do not open shared documents or email attachments unless you are expecting them and trust the person who sent them, and only use secure, trusted networks. For more information, see Phishing & ScamsSecure Your Devices, and Secure Your Internet Connection on the U-M Safe Computing website.

Questions, Concerns, Reports

Please contact ITS Information Assurance through the ITS Service Center.