Security

Information Security Attack Spotlight

This section provides an overview of real cybersecurity threats the A-State IT Security team has encountered with the goal of helping prepare users to identify future threats.

Information Security Attack Spotlight

SharePoint Phishing Campaign

This article highlights a campaign seen on campus during the second week of May 2026. This malicious phishing campaign saw users receive legitimate SharePoint file sharing emails from threat actors external to our organization. The following details specific components of this email and takes a deeper dive into what indicators exist within the email. 

Sharepoint Attack Spotlight.jpeg

Having reviewed all components of the email and not just the header, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.  

What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email Was Interacted With: If you received and interacted with an email before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.  

 


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session. 

 

Information Security Attack Spotlight

Immediate Attention Required (URGENT) Phishing Campaign

This article highlights a campaign seen on campus during the last week of June and first week of July 2026. This malicious phishing campaign saw users receive emails from already compromised internal users with a malicious form to fill out. The following details specific components of this email and takes a deeper dive into what indicators exist within the email. 

Immediate Attention Required (URGENT) Sanitized.png

Immediate Attention Required (URGENT) WIX Site.png

Having reviewed all components of the email and the underlying form, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.  

What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email or Form Was Interacted With: If you received and interacted with an email or form before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.  


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session. 

Information Security Attack Spotlight

Summer Part Time Job at ASU Phishing Campaign

This article highlights a campaign seen on campus during the last week of June and first week of July 2026. This malicious phishing campaign saw users receive emails from already compromised internal users with a malicious form to fill out. The following details specific components of this email and takes a deeper dive into what indicators exist within the email. 

Summer Part Time Job at ASU Phish Sanitized.png

Having reviewed all components of the email and the underlying form, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.  

What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email or Form Was Interacted With: If you received and interacted with an email or form before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.  


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session. 

Information Security Attack Spotlight

Student Report Phishing Campaign

This article highlights a campaign seen on campus during the second week of May 2026. This malicious phishing campaign saw users receive emails from a compromised user account in our organization. The following details specific components of this email and takes a deeper dive into what indicators exist within the attack.


Compromised Account.jpg

  • #1 – Compromised Account: Occasionally threat actors will successfully gain access to an A-State employee's account. This makes phishing emails harder to identify because they come from an offical A-State email address. When attacks like this occur, users must use other sources of information to determine the legitimacy of an email (e.g., Institutional knowledge of job roles and duties). In this instance the sender address did not match who they were claiming to be, so this helps to identify it as suspicious.
  • #2 – Creating a sense of urgency: Threat actors will lean on publicly available information to help create a sense of urgency and legitimize some content in the attack. In this instance, the threat actor is doing this by claiming the content of this message is about an ongoing student report that is being shared on behalf of Martha Spack. 
  • #3 – Link to another document: The largest crack in this attack foundation is the link provided by the attacker. In this case the link directs to Google Drive where a malicious file can be downloaded. A-State employs various tools to help secure our environment. Threat actors know this and will attempt to direct you out of our environment and into another less secure one to increase their effectiveness. 
  • #4 – Unauthorized Software: Here the attacker calls out the name of the tool that can be downloaded from the Google Drive link. Upon researching this tool, it can be found that it is a remote support tool that allows connection to another computer. There are a couple of key issues here:
    •  First is that there would be no need to remote into a computer to share the document mentioned above.
    • The other is that Zoho Assist is not an Arkansas State University approved tool. 

Having reviewed all components of the email and not just the header, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.


What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email Was Interacted With: If you received and interacted with an email before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.  

 


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session. 

 

Information Security Attack Spotlight

"Downsizing" Phishing Campaign

This article highlights a campaign seen on campus during the second week of May 2026. This malicious phishing campaign saw users receive emails from a compromised user account in our organization. The following details specific components of this email and takes a deeper dive into what indicators exist within the email. 

Screenshot 2026-05-15 105058.png

Remember: Even emails sent from legitimate accounts can be malicious if the account has been compromised. Always verify suspicious requests before taking action.  


What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email Was Interacted With: If you received and interacted with an email before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded. 

 


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session.