February 6, 2026
Ongoing phishing/smishing campaign
Denison Security
Denison’s cybersecurity intelligence has observed a persistent, multi-stage phishing and smishing campaign. We track this threat actor as BLUECRAB, and we have observed them before.
The threat actors use a similar pattern of behavior:
- Using a maliciously crafted email, phish a victim and steal both the victim’s password and the victim’s personal cell phone number.
- Send a second “smish” (phish via SMS) to the victim, claiming that the victim’s account is pending deactivation, and engage them in a conversation.
- When the victim replies, attempt to log in as the victim, using the phished password.
- On the multi-factor authentication (Duo) step, choose SMS. Simultaneously tell the victim that they need to verify their cell phone number by sending a SMS code, and to send that code in the same text message thread.
- Use the smished multi-factor authentication code to log in as the user, then change the password.
- Send other users more phishing messages, either to steal credentials or money.
The “smish” message might look something like:
Attacker:
Hello is this [victim name]?
Attacker:
Confirm if you applied to terminate your current school email (<username>[@]denison[.]edu)Confirm YES or NO (So NO means that I don’t want to terminate my email) to avoid complete shutdown of your email and loss of all your files.
Helpdesk[@]denison[.]edu
Victim:
NO
Attacker:
Alright! If [XXXX] matches the last 4 digits of the phone number on your profile account. You will a text from the system now with a code. Which is what you will text back to avoid account shutdown. Okay?
Victim:
okay
Attacker:
A verification code sent to your phone, what is the code?
Victim:
[XXXXXXX]
Attacker:
Okay
At this point, the attacker has successfully gained access to the victim’s account. From here, we have observed them doing several things:
- Directly phishing other users within the denison[.]edu domain
- Directly attempting to scam for money
- Schedule or delay sending messages, to be sent (even after the account is remediated)
- Changing email settings to obfuscate their tracks
- Deleting email messages that indicate malicious intent
Never give out a multi-factor authentication code that you did not request yourself! Never provide your password anywhere EXCEPT for Denison’s single sign-on page. You can verify the login page by checking the address bar: the domain should be identity.denison.edu. And, if you receive a suspicious email message, forward it to isitsafe@denison.edu to report it as phishing.