Dear York College Community,
CUNY has identified an active phishing campaign in which compromised Microsoft 365 email accounts are being used to send fraudulent messages that appear to come from official CUNY or college financial aid offices. These emails often claim that urgent action is required to receive financial aid grant disbursements or funding opportunities. Samples of recent phishing attempts are attached for your awareness.
Recent indicators of this security threat include:
- Subject lines that appear to reference CUNYfirst
- Subject lines such as “Required Action for Grant Funding Eligibility” or “Immediate Response Required for Grant Disbursement”
- Messages urging immediate action, such as clicking a link or replying with personal information
If you believe you may have been affected or responded to one of these messages, please contact the York College Help Desk immediately.
Important Reminders to Protect Yourself:
- Review the CUNY advisories on avoiding scams, including “How to Protect Yourself Against Secret Shopper, Personal Assistant, and other Online Scams!” and phishing guidance at security.cuny.edu under CUNY Issued Security Advisories.
- Do not reply to unexpected or unusual emails from any sender.
- Be cautious when an “external source” warning banner appears at the top of an email.
- Never provide personal information or passwords via email. If you believe a request may be legitimate, contact the institution or company directly using a verified phone number.
- Avoid clicking links or opening attachments in unsolicited messages. Type the organization’s web address directly into your browser instead.
- Do not reuse the same password across multiple accounts. Attackers often attempt to access additional services using compromised credentials.
- Change all passwords immediately if you suspect any account may be compromised.
- Be especially careful when reading email on mobile devices, where phishing signs may be harder to spot.
- Remember that official communications will not request personal information by email.
- Review the CUNY Personal Assistant Scam and Phishing Advisories at security.cuny.edu under CUNY Issued Security Advisories.
- Complete the Cyber Security Awareness Training available in Brightspace.
Thank you for your continued vigilance in helping protect the York College and CUNY community from cybersecurity threats.
Warm regards,
YORK IT/ CIS
Sample Phishing Email:
2nd Sample Phishing Email: