Security

February 6, 2026

Ongoing phishing/smishing campaign

Denison Security

Denison’s cybersecurity intelligence has observed a persistent, multi-stage phishing and smishing campaign. We track this threat actor as BLUECRAB, and we have observed them before.

The threat actors use a similar pattern of behavior:

  1. Using a maliciously crafted email, phish a victim and steal both the victim’s password and the victim’s personal cell phone number.
  2. Send a second “smish” (phish via SMS) to the victim, claiming that the victim’s account is pending deactivation, and engage them in a conversation.
  3. When the victim replies, attempt to log in as the victim, using the phished password.
  4. On the multi-factor authentication (Duo) step, choose SMS. Simultaneously tell the victim that they need to verify their cell phone number by sending a SMS code, and to send that code in the same text message thread.
  5. Use the smished multi-factor authentication code to log in as the user, then change the password.
  6. Send other users more phishing messages, either to steal credentials or money.

The “smish” message might look something like:

Attacker:

Hello is this [victim name]?

Attacker:

Confirm if you applied to terminate your current school email (<username>[@]denison[.]edu)Confirm YES or NO (So NO means that I don’t want to terminate my email) to avoid complete shutdown of your email and loss of all your files.
Helpdesk[@]denison[.]edu

Victim:

NO

Attacker:

Alright! If [XXXX] matches the last 4 digits of the phone number on your profile account. You will a text from the system now with a code. Which is what you will text back to avoid account shutdown. Okay?

Victim:

okay

Attacker:

A verification code sent to your phone, what is the code?

Victim:

[XXXXXXX]

Attacker:

Okay

At this point, the attacker has successfully gained access to the victim’s account. From here, we have observed them doing several things:

  • Directly phishing other users within the denison[.]edu domain
  • Directly attempting to scam for money
  • Schedule or delay sending messages, to be sent (even after the account is remediated)
  • Changing email settings to obfuscate their tracks
  • Deleting email messages that indicate malicious intent

Never give out a multi-factor authentication code that you did not request yourself! Never provide your password anywhere EXCEPT for Denison’s single sign-on page. You can verify the login page by checking the address bar: the domain should be identity.denison.edu. And, if you receive a suspicious email message, forward it to isitsafe@denison.edu to report it as phishing.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.