Summer Part Time Job at ASU Phishing Campaign
This article highlights a campaign seen on campus during the last week of June and first week of July 2026. This malicious phishing campaign saw users receive emails from already compromised internal users with a malicious form to fill out. The following details specific components of this email and takes a deeper dive into what indicators exist within the email.
-
#1 – Header information: A solid first stop in identifying potentially malicious emails. Phishing emails fabricate a sense of emergency in order to trick readers into providing sensitive information. Legitimate emails may sometimes contain these "urgent" key words, but generally these indicate a malicious email.
-
#2 - “Who” is emailing you: Where external or unrecognized senders may be easily dismissed by the reader, this particular campaign leveraged a compromised internal account to circumvent that. In this context of university account issues, this sort of email would never come from a student (smail.astate.edu) account.
-
#3 – Investigation of inserted links: Having created a sense of urgency in this email and borrowing "legitimacy" from an internal account, an embedded link to the real threat (a malicious website requesting sensitive information) covers up what would otherwise stand out as suspicious. By hovering over this embedded link instead of clicking on it, the reader can see this directs to Wix site set up by the threat actor. This is not a service Arkansas State University uses and is another indicator this is malicious.
-
#1 – Website Header information: Shows the visitor that this was a website created on an external service.
-
#2 - Fake Logo: Displays a fake Microsoft logo to create a sense of legitimacy.
-
#3 – Further Creating a Sense of Urgency: This form description reinforces that a delay in immediate action will result in unwanted consequences. Not only does this form attempt gain one accounts information from the reader, but it also asks for a second accounts information. This would likely be a secondary account used as a recovery method.
-
#4 – Password Compromise: The form attempts to make the reader believe this is actually a login screen and not just a custom form. Despite this attempt, readers can see through this by the spelling mistakes and the false claims this is "Protected by Admin".
-
#5 - Submit vs Login: Instead of displaying a "login" or other similarly worded phrase to show this isn't a form, it instead shows "submit" which is another indication this is a malicious form and not a secure space to input sensitive information.
Having reviewed all components of the email and the underlying form, we can safely confirm this email is malicious and should be reported to security@astate.edu so that it can be removed from everyone's inbox.
What You Should Do
Be Skeptical of Unknown Senders: If you receive an unexpected or unusual email, verify its legitimacy by contacting the sender through a known and trusted channel.
- Requests to Respond to Personal E-Mails: If you receive an e-mail from an A-State student or faculty, and there is a request to respond with information to a personal e-mail (e.g. Gmail, Yahoo, Hotmail etc.) please do not respond and forward to security@AState.edu for review to determine the legitimacy of the sender/e-mail.
- Report Suspicious Emails: If you receive a suspicious email, do not respond, click any links, or download attachments. Instead, report it by forwarding the email to security@AState.edu.
- A Suspicious Email or Form Was Interacted With: If you received and interacted with an email or form before determining it was suspicious, please take the following steps:
-
- Immediately take steps to reset your account password. This crucial step helps ensure that any access a threat actor may have gained is revoked.
-
- If malicious attachments are downloaded to your asset, be sure to delete them.
-
- Contact security@AState.edu to report the incident. Be sure to provide details of the incident, including forwarding the malicious email to our team and detailing if attachments were downloaded.
Interested in additional information security training? The A-State IT Security team holds regular in-person training sessions on campus. Be sure to check the Daily Digest for advertisements on the next training session.

