Security

December 8, 2025

Spear phishing attacks on the rise

Denison Security

Denison’s cybersecurity intelligence has observed a sharp rise in the number of “spear phishing” attacks, or personalized attacks designed to steal your identity, information, or money. While spear phishing is not new, we have observed a significant increase in the number of messages being delivered.

Recent campaigns that match this profile include the following red flags:

  • They originate from a Gmail, Yahoo, or Proton mail account, not a Denison account. They also do not originate from the domain that they purport to originate from.
  • They are sent only to you, not to a mailing list or using BCC.
  • They include some personal touches, including your name, your role at Denison, your skills, or your interests.
  • They include an “ask” for some personal information to “get the process started,” including (but not limited to):

    • Age
    • Banking information
    • Resumé or CV
    • Work experience
  • They often include grammatical or formatting errors, including extra spaces, mismatched fonts, or missing punctuation.
  • The adversaries appear to be targeting anyone they can get information on, including students, staff, and faculty.
  • The personal touches are generally derived from public directory information, including your name and role at Denison. However, we caution you to be careful about what information you share online, including on social media or networking apps, like LinkedIn.

    While Denison makes great efforts to prevent these messages from reaching your inbox, no filter or classification model is perfect. Reporting suspicious messages by forwarding them to isitsafe@denison.edu is the fastest way to find out if a message malicious; plus, it automatically removes and reports the message if it is malicious.

    Edit (Feb 17, 2026): We are now attributing this spear phishing campaign to a threat actor we track as MIDNIGHTCRAB.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.