Information Services > Security > News & Updates > Recover Pending Messages Phishing - 09/29/21

Recover Pending Messages Phishing - 09/29/21

Screenshot of malicious email:

A screenshot of a malicious email. The email attempts to trick victims into clicking on a malicious link.


On September 29th, 2021, an external (gmail) address was used to target DePaul inboxes with phishing materials.

The malicious email claims that the recipient needs to click a (malicious non-DePaul) link to recover (non-existant) pending messages. The email attempts to spoof Information Services.

The link takes victims to a non-DePaul website, which is set up by the malicious actors to harvest the credentials of victims. The credential harvesting website uses some Microsoft logos in an attempt to make the page look more legitimate.

It is always important to remain vigilant when handling email, even when it appears to be "official" looking. Email addresses, names, and login portals can be spoofed and imitated. Compromised email accounts (e.g. if a fellow DePaul community member fell victim to phishing) are often used to target the community. Keeping your DePaul account secure helps keep the entire community secure.

Some indicators that this email is malicious:
- Grammatial errors
- A link to a non-DePaul website
- Impersonation of DePaul departments

Anyone who has entered their credentials into this scam should immediately change their password and report the incident to security@depaul.edu.​