Security

November 16, 2025

Active phishing campaign impersonating Denison accounts

Denison Security

Denison’s cybersecurity intelligence has observed an aggressive phishing campaign that has been targeting Denison over the past several weeks. This campaign has included multiple messages sent by different means, but all messages attempt to get a user to click on a link and input account credentials, such as usernames and passwords.

In this campaign, we have noticed impersonation of Denison accounts, including the Service Desk. This campaign includes a link or button that goes to a malicious webpage. We have observed the following domains.

  • vdgmentorias[.]com
  • du[.]vdgmentorias[.]com

You can see the domain by hovering over the link with your mouse on a computer and looking in the bottom-left corner. The domain should match denison.edu.

Denison will never ask for your password by email, by Google Form, or by calling. If you receive such a message, please forward it to our reporting mailbox at isitsafe@denison.edu. If you have accidentally interacted with a message or think you might’ve sent credentials, immediately contact the Service Desk.

Edit (Feb 17, 2026): We now attribute this phishing campaign to a threat actor we track as MIDNIGHTSTONEFISH.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.