A phishing email is circulating from a random Gmail account claiming to be “HELP DESK,” with an out-of-date university logo and a giant QR code that purports to lead to a verification system for your school account. This is fake! If you visited the QR code website, please open a request with security@illinois.edu at your earliest opportunity to receive guidance on protecting your account.
In the wake of the Canvas hack in May 2026, we are likely to see more phishing and spear phishing attacks in the near future. Please be extra vigilant and reach out to security@illinois.edu immediately if you suspect any communication to be malicious. More guidance available here.
An example of a likely legitimate automated SharePoint message from a potentially compromised account is below.
We have seen a few examples of fake messages from Russian domain (.ru) email addresses purporting to be notifications about undeliverable voicemail messages. Do not open any attachments! They should be marked with the Report Spam button.
There are reports of fake Geek Squad subscription invoices going around to both personal and university email addresses. An example is included here. Use the “Report Spam” button in Outlook to report and delete these messages. In personal email accounts, mark the message as Spam and/or delete it.
There is a scam going around where a Behavioral/Academic Support report is purportedly sent by the Vice Chancellor for Student Affairs to faculty. An example is below. Do not click the link or run anything that downloads. Use the “Report Phishing” feature of Outlook to report it to the campus email team. Thank you!
Please be aware of a new phishing/impersonation scheme where an unidentified phone number texts an employee’s personal cell phone and impersonates a college leader like Dean Elliott or former Dean Jeff Brown. The end goal is a common scam — the purchase and delivery of Amazon gift cards. An example can be seen in this post.
While it’s undetermined how the scammer acquired the personal phone numbers AND made the employment connection, it is suspected it’s from a data breach of a third-party platform where phone contacts were shared.
If you get an unexpected text from Dean Elliott or another member of college or campus leadership — especially from a number you don’t already have in your contacts — please either delete or confirm its authenticity through another means before responding. Most smartphones and carriers will allow you to make a message as spam or block the number; that is also a reasonable step.
We’ve received several reports of the scam going around. This is a message purporting to be from the “Vice President for Public Affairs” via a Harvard email address about a behavioral/academic support student report for a class. Do not click the link or run anything that downloads. Use the “Report Spam” feature of Outlook to report it to the campus email team. Thank you!
There is a scam campaign going around this week encouraging people to update and validate their Office accounts. This is not a legitimate message and you should not click the link or enter your credentials in the site it goes to. If you do click the link and your password is compromised, it will be automatically scrambled and you will have to reset it before you can access university resources.
Remember to make the message with the “Report Spam” button in Outlook, and reach out to your local IT support if you have any questions or concerns!
Another version of the “sent from yourself, blank with only an attachment” scam campaign is circulating today. Please be vigilant about emails in this format, especially ones offering too-good-to-be-true benefits or urging immediate action to avoid dire consequences. Check with your local IT support for a second opinion before taking any action, and use the Report Spam feature of Outlook to add malicious emails our campus filter to prevent further spread.
A phishing campaign email is going around prompting people to update their Office 365 portal/account details to avoid losing access. This is not a legitimate message. Do not click any links or provide any login credentials! Report the message as spam in Outlook and delete it.