February 6, 2026
Denison’s cybersecurity intelligence has observed a persistent, multi-stage phishing and smishing campaign. The threat actors use a similar pattern of behavior, using a maliciously crafted email to phish a victim and steal both the victim’s password and the victim’s personal cell phone number. The attacker then smishes the user and steals a multi-factor authentication code to access the victim’s account. With the account, they send other users more phishing messages, either to steal credentials or money.
Read more...
February 3, 2026
Denison’s cybersecurity intelligence has observed a rise in malicious Gmail addresses being used in cyberattacks. While these email addresses are generally quickly shut down, it’s important to not engage with them and report suspicious behavior. In many recent phishing messages received by Denison email accounts, the origination or reply address are bogus Gmail accounts. If you receive an email purporting to be from a Denison user, ensure that the email address’s domain ends with denison.edu. Attackers often add components to an email address to make it look like it came from a Denison mailbox, even though it didn’t.
Read more...
December 15, 2025
Denison’s cybersecurity intelligence is aware of multiple, ongoing phishing campaigns. These are very active campaigns, and they are attempting to steal account information in order to steal financial and student data. We are attributing this campaign to a threat actor we track as BLUECRAB. Common themes in BLUECRAB attacks include account compromise originating from spear phishing leading to larger lateral phishing attacks. We believe that BLUECRAB‘s attacks are financially motivated….
Read more...
December 8, 2025
Denison’s cybersecurity intelligence has observed a sharp rise in the number of “spear phishing” attacks, or personalized attacks designed to steal your identity, information, or money. While spear phishing is not new, we have observed a significant increase in the number of messages being delivered. Recent campaigns that match this profile include the following red flags: They originate from a Gmail, Yahoo, or Proton mail account, not a Denison account….
Read more...
December 1, 2025
Denison’s cybersecurity intelligence has been made aware of a financial scam targeting faculty, administrative staff, and support operating staff. If you receive a suspicious message, please forward it to isitsafe@denison.edu. What is the message trying to steal? The message attempts to steal sensitive personal information, including social security numbers. What do I do if I get a malicious message? How can I tell the message is malicious? Denison’s ONLY partners…
Read more...
November 16, 2025
Denison’s cybersecurity intelligence has observed an aggressive phishing campaign that has been targeting Denison over the past several weeks. This campaign has included multiple messages sent by different means, but all messages attempt to get a user to click on a link and input account credentials, such as usernames and passwords. In this campaign, we have noticed impersonation of Denison accounts, including the Service Desk. This campaign includes a link…
Read more...
November 13, 2025
Denison’s cybersecurity intelligence has observed a tricky phishing attack, targeting Denison using Google Calendar invitations. Attackers are sending fake calendar invites, taking advantage of calendar invitation settings designed to make it easy to schedule meetings. This phishing technique sends a Google Calendar invitation directly to your calendar, which bypasses email spam filters. By default, Google automatically adds calendar invites directly to your calendar. The attackers’ invitations appear genuine alongside your…
Read more...