Skip to main content

Immediate Attention Required (URGENT) Phishing Campaign

This article highlights a campaign seen on campus during the secondlast week of MayJune 2026. This malicious phishing campaign saw users receive legitimate SharePoint file sharing emails from threatalready actorscompromised externalinternal users with a malicious form to ourfill organization.out. The following details specific components of this email and takes a deeper dive into what indicators exist within the email. 

Sharepoint Attack Spotlight.jpegImmediate Attention Required (URGENT) Sanitized.png

  • #1 – Header information: A solid first stop in identifying potentially malicious emails. InPhishing thisemails attack however, the traffic is legitimate SharePoint traffic. This occurs because another organization has either been maliciously created or has hadfabricate a securitysense incidentof leadingemergency in order to theirtrick usersreaders beinginto ableproviding tosensitive shareinformation. Legitimate emails may sometimes contain these "urgent" key words, but generally these indicate a malicious documents. email.

  • #2 - “Who” is sharing the file withemailing you: ItWhere canexternal or unrecognized senders may be trickyeasily fordismissed by the reader, this particular campaign leveraged a threatcompromised actorinternal account to perfectlycircumvent manipulate the necessary fields in a malicious email where there are no suspicious gaps.that. In this instance,context thatof isuniversity displayedaccount inissues, thethis “who”sort isof sharingemail would never come from a filestudent with(smail.astate.edu) you.account. 

  • #3 – CreatingInvestigation of inserted links: Having created a sense of urgency in this email and borrowing "legitimacy" from an internal account, an embedded link to the real threat (a malicious website requesting sensitive information) covers up what would otherwise stand out as suspicious. By hovering over this embedded link instead of clicking on it, the reader can see this directs to Wix site set up by the threat actor. This is not a service Arkansas State University uses and is another indicator this is malicious.

Immediate Attention Required (URGENT) WIX Site.png

  • #1 – Website Header information: ThreatShows actorsthe willvisitor leanthat this was a website created on publiclyan availableexternal informationservice.

  • #2 - Fake Logo: Displays a fake Microsoft logo to help create a sense of urgencylegitimacy. and

    legitimize
  • some
  • content

    #3 – Further Creating a Sense of Urgency: This form description reinforces that a delay in theimmediate attack.action Inwill result in unwanted consequences. Not only does this instance,form attempt gain one accounts information from the threatreader, actorbut isit doingalso thisasks byfor manipulatinga fieldssecond toaccounts implyinformation. thisThis messagewould comes from Dr. Robin Myers. Sometimes traffic like this canlikely be legitimate,a sosecondary reviewingaccount theused message as a wholerecovery helps to narrow things down.method.  

  • #4 – FooterPassword informationCompromise: InThe form attempts to make the reader believe this instance,is actually a login screen and not just a custom form. Despite this attempt, readers can see through this by the largestspelling crackmistakes inand the false claims this is "Protected by Admin". 

  • #5 - Submit vs Loginattacks: foundationInstead isof thedisplaying footera information"login" SharePointor hasother automaticallysimilarly addedworded phrase to theirshow traffic.this Thisisn't clearlya conveysform, thatit theinstead messageshows originates from SRI SARVARAYA SUGARS LTD's SharePoint,"submit" which is another indication this is a malicious form and not associateda withsecure Arkansasspace Stateto University.input sensitive information. 

Having reviewed all components of the email and not just the header,underlying form, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.  

What You Should Do 

Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel. 


  • Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail. 
  • Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu. 
  • A Suspicious Email Was Interacted With: If you received and interacted with an email before determining it was suspicious, please take the following steps:  
    • Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.  
    • If malicious attachments are downloaded to your asset, be sure to delete them.  
    • Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.  

 


Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session.