Phishing scam: "Important Alert from McGill University Admin"

News

Update - Tuesday, October 10, 2017:
There is a phishing email targeting the McGill community, with the subject "Important Alert from McGill University Admin" and signature "Privacy Policy | Customer Support, Office 365 Mailbox Support Team". The message asks recipients to Validate Email Account. Click the screenshot on the left to view an example of the message.

This email is a fraudulent attempt to gain access to your personal information. If you have already clicked on the link in this email and submitted any personal information, you should change your McGill Password as soon as possible. See the McGill Password Reset Checklist for instructions.

If your McGill account was already compromised, it may have been locked by McGill Information Security; in that case, you must contact the IT Service Desk (514-398-3398) to unlock your account.


Original announcement, Monday August 24, 2017:
There is a phishing email targeting the McGill community, with the subject "Important Alert from McGill University Admin" and signature "Privacy Policy | Customer Support, Office 365 Mailbox Support Team". The message asks recipients to Validate Email AccountSee an example of this phishing message below.

Please DO NOT click on the link or reply to the message. Delete this email immediately! It does NOT come from a McGill source.

This email is a fraudulent attempt to gain access to your personal information. If you have already clicked on the link in this email and submitted any personal information, you should change your McGill Password as soon as possible. See the McGill Password Reset Checklist for instructions.

If you have received a phishing email or suspect that you have, please report it, by sending the message as an attachment to phishing [at] mcgill.ca immediately.

Quick links:


Example of this phishing message:

Sender name & address: <looks like a valid McGill person>
Subject: Important Alert from McGill University  Admin

Dear <email address> ,

This is to notify all Students, Staffs/Faculty, of MgGill University that we are validating all McGill network user accounts.

Kindly confirm that your account is still in use by clicking the validation link below:

Validate Email Account (this is the fraudulent link)

Thank you,

Privacy Policy | Customer Support
©2017 Office365 Mailbox Support Team. All Rights Reserved.