Office of Information Technology
March 7, 2024
Tags Phishing Email (on campus)

Phony Payroll Notifications from non-Brown domains

Phish Bowl Alerts

Be on the lookout for phony payroll emails from non-Brown sources. To protect yourself from phishing attempts such at these, it is critical you thoroughly inspect the details of the message to confirm its authenticity. This example contains several glaring red flags - the sender is spoofing a vanderbilt[dot]edu domain (entirely outside our institution), the message has next to no formatting or aesthetic authenticity, and the included link replaces the letter "O" with zeros. It is critical we begin to build a culture of healthy security skepticism across Brown. Take your time when reviewing your emails - do not create a false sense of urgency for yourself. If a message looks suspicious or simply doesn't feel right, confirm by other means. When in doubt, reach out!

A screenshot of a bogus payroll email from a spoofed Vanderbilt email address.