Phish Bowl

Welcome to the Phish Bowl

This page is a blog-style list of recent phishing attempts that our Information Security team has identified. Entries are organized below by "most recent." This will allow users to get a peek at how attempts to compromise VIU's information security will present themselves in your Inbox.

If you ever find yourself on the receiving end of something that seems "phish-y" to you, the examples below can help you to know for sure, so check back often. If you're still unsure, use the Report phishing links at the bottom of each entry.


Phish: Fake National Bank VIU RRSP records scam

Published: September 28, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign targets university employees by impersonating Vancouver Island University pension services and National Bank Direct Brokerage. The email claims that your September RRSP contribution summary is ready and includes a password-protected PDF attachment. The attackers provide a document access code (mULW9r8968H2) to open the file. Locking the PDF prevents automated email scanners from reading the document and finding the malicious link. Inside the document, a link sends users to a fake website set up to steal login details.

Do not open unexpected attachments, enter access codes or click links in unsolicited pension documents. Legitimate university pension updates will not come from external domains or combine multiple bank names. If you receive this message, report it immediately through Outlook.

Email details

Subject: [External] Vancouver island university RRSP Records September

You don't often get email from [name-redacted]@canadawest[.]cc. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: National Bank Direct Brokerage <[name-redacted]@canadawest[.]cc>

To: [Internal Employee]


Registered Retirement Savings Plan


Your RRSP contribution summary is attached, including total contributions and employer matching summary.

🔒 Document Access Code
mULW9r8968H2

Final 2025 contribution deadline is September 1st 2026 for maximum tax benefit.

This document requires Adobe Acrobat Reader.
Download Adobe Reader


Vancouver Island university • BMO Pensions

This is an automated notification, Please do not reply directly to this email.

📎 1 attachment: Vancouver island university RRSP-September-520139.pdf (37.1 KB)
VANCOUVER ISLAND UNIVERSITY RRSP STATEMENT
SEPTEMBER 28, 2026

PREPARED FOR
[Internal Employee]

Your RRSP contributions with Vancouver island university are available for your records. Please review your allowed deduction limit and available deductions.

STATEMENT DETAILS
REFERENCE RRSP-520139
EMPLOYER'S PRPP CONTRIBUTIONS **,***.00
DEFERRED GROWTH **,****.**

Questions? We've got answers! Find everything you need to access your rrsp online. Visit our tax support hub for FAQs, dates, step-by-step video instructions and much more.

Vancouver island university Retirement Services

REGISERED RETIREMENT SAVINGS PLAN
VANCOUVER ISLAND UNIVERSITY | CONFIDENTIAL & PERSONAL

Phishing cues

! Compromised external account with External Email banner
  • The message comes from a compromised external account ([name-redacted]@canadawest[.]cc) and displays VIU's External Email warning banner. Genuine messages about employee benefits come directly from internal VIU email addresses.
! Conflicting financial institutions and senders
  • The sender displays National Bank Direct Brokerage, the email footer lists BMO Pensions, and the document claims to come from Vancouver Island University Retirement Services. Authentic university pension communications never mix competing banks.
! Password-protected PDF to bypass security filters
  • The attached PDF (Vancouver island university RRSP-September-520139.pdf) is locked with a password (mULW9r8968H2). Attackers encrypt files so email security tools cannot scan the document or check the web link inside.
! Hidden link to steal login credentials
  • The document asks you to select VIEW RRSP SUMMARY. This button directs you to an external website (red-flower-047159610.5.azurestaticapps[.]net) designed to steal your university login credentials.
! Spelling, capitalization and tax deadline errors
  • The email and PDF contain multiple obvious errors. These include lowercase school branding ("Vancouver island university"), spelling mistakes ("REGISERED RETIREMENT SAVINGS PLAN") and false Canadian tax deadlines ("September 1st 2026").
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.

Phish: Fake Dell order confirmation callback scam

Published: September 16, 2026  |  Category: Security Awareness PhishBowl

This scam uses real Dell order emails to run a fake customer support phone scam. The attacker places an order for software costing $736.09 and puts a fake helpline phone number inside the shipping and billing address lines. The email greets the reader as "Hello Order" to create panic about a charge they did not make. The scammers hope you will call their fake number to cancel the purchase so they can steal your credit card details.

Do not call the phone numbers listed in the message or click any links. If you receive an order confirmation for something you did not buy, check your credit card account directly or report the email through Outlook.

Email details

Subject: [External] We have your order | Dell Purchase ID: 2009835261727

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Dell | Order Received <received[@]order.dell[.]com>

To: abubakarsadiqmuhamma771[@]gmail[.]com


Thanks for your order.

You'll receive an order confirmation soon.

Manage your orders

Hello Order,

We have your order that you placed on September 16, 2026. Your Dell purchase ID is 2009835261727. Next, you should receive an order confirmation.

To manage your orders, you'll need to create a My Account using the same email as this purchase.

Order Details
Microsoft Project Standard 2024 All Languages Online Product Key License 1 License Downloadable Click to Run ESD NR Qty: 1 $679.99

Subtotal: $679.99
Shipping &/or Handling: $0.00
Estimated Tax: $56.10
Total (USD): $736.09
Ship To:
Confirmed Order
Helpline 802 547 4437
Call Our Sales Team
Round Rocks, TX. 78682-Round Rocks
(802) 5474437

Shipping method: Standard
Bill To:
Confirmed Order
Helpline 802 547 4437
Call Our Sales Team
Round Rocks, TX. 78682-Round Rocks
(802) 5474437

Payment method: CreditCard
Amount: USD $736.09

Do more online while you wait for your order.

My Account: Review order history, change your shipping address, start a return or exchange, get help or cancel your order.

Review frequently asked questions: Quickly find answers to common support questions.

Thank you for choosing Dell Technologies.

Phishing cues

! Fake phone number hidden in shipping address
  • The scammers put a fake phone number (802 547 4437 / (802) 5474437) directly inside the Ship To and Bill To address lines. They label it "Helpline" and "Call Our Sales Team" so you will call them to dispute the $736.09 charge.
! Wrong email address in the "To" line
  • The message is sent to an outside Gmail account (abubakarsadiqmuhamma771[@]gmail[.]com) instead of your VIU email address. Scammers often send these emails to large lists or blind copy (BCC) groups.
! Real store email used to bypass filters
  • The message comes from a genuine Dell address (received[@]order.dell[.]com). The attackers submit orders through the real Dell website with fake address lines so the email passes spam filters.
! Odd greeting and high price tag
  • The message starts with "Hello Order" because the scammer typed the word "Order" as the customer first name. The high total ($736.09) is meant to shock you into calling without thinking.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.

Phish: Spoofed VIU MBA program support package scam

Published: September 11, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign impersonates the Vancouver Island University MBA Program using a spoofed sender address. Attackers combine contradictory lures by referencing a "Non Disclosure Agreement" in the subject line while offering a "company support package" in the email body. Their goal is to deceive recipients into clicking the Authorize Support button to steal credentials or compromise devices.

Do not click links or select Authorize Support in unexpected messages. Legitimate university notifications will not arrive with an External Email warning while claiming to originate from an internal VIU program. If you receive this message, report it immediately through Outlook.

Email details

Subject: [External] [[Targeted Department]]: Non Disclosure Agreement.

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Vancouver Island University MBA Program SecureStreamer · Enterprise ShareFile <no-reply[@]viu[.]ca>

To: [Targeted Department]


Vancouver Island University MBA Program Mail

Hi [Targeted Department],

A secure company support package has been made available for [Targeted Department].

Authorize Support

Please use the link above only on your authorized work computer.

Regards,
Viu Mail

Phishing cues

! Spoofed sender address with External Email banner
  • The sender claims to be the VIU MBA Program and displays no-reply[@]viu[.]ca. However, the External Email banner and [External] tag confirm the email originated outside VIU servers. Authentic internal messages from VIU departments do not carry external warning banners.
! Contradictory subject line and body lures
  • The subject line refers to a "Non Disclosure Agreement," while the message body claims to share a "company support package" with an Authorize Support button. Attackers often combine mismatched templates from different scam kits.
! Deceptive security instructions
  • Instructs you to use the link "only on your authorized work computer." Attackers use this psychological tactic to mimic legitimate workplace IT compliance rules and build false trust.
! Inconsistent branding and functional inbox targeting
  • The email targets a departmental inbox with a generic greeting ("Hi Advising,") and signs off as "Viu Mail" with improper capitalization. Official VIU communications follow consistent naming and branding standards.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Executive impersonation mobile number request

Published: August 27, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign impersonates VIU President Dennis Johnson using random external Gmail addresses. Attackers reference university leadership in the subject line to establish false authority and create urgency with follow-up messages like "WAITING FOR YOUR RESPONSE?". Their goal is to obtain your mobile number to transition communication to SMS text messaging, which commonly leads to gift card fraud or urgent wire transfer requests.

Never provide personal mobile phone numbers or agree to financial transactions over email or text. University leadership will not contact employees from personal Gmail accounts to request gift cards or urgent payments. Always report suspicious messages through Outlook.

Email details

Subject: [External] Re: Dennis Johnson

You don't often get email from b62753139[@]gmail[.]com. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: JOB FOR YOU! <b62753139[@]gmail[.]com>

To: [Internal Employee]


WAITING FOR YOUR RESPONSE?

On Thu, Aug 27, 2026 at 7:43 AM JOB FOR YOU! <b62753139[@]gmail[.]com> wrote:

[First Name]

What's the best mobile or work number to reach you via text?

Warm regards.

Phishing cues

! Executive name in subject with random Gmail address
  • References VIU President Dennis Johnson in the subject line, but was sent from a random external Gmail account (b62753139[@]gmail[.]com) with a mismatched display name ("JOB FOR YOU!").
! External email warning banner
  • Displays VIU's External Email warning banner. Genuine communications from VIU leadership originate internally from @viu.ca addresses.
! Off-platform mobile phone and SMS lure
  • Asks for your personal mobile number to move the conversation to text messaging, a common tactic used to bypass email security and initiate gift card fraud.
! False urgency and pressure tactics
  • Uses all-caps follow-up messaging ("WAITING FOR YOUR RESPONSE?") and fake reply threading ("Re:") to create artificial urgency and pressure you into a quick reply.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake contractor bid opportunity

Published: August 13, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign uses compromised external accounts to send unsolicited invitations for contractor bid opportunities. The email directs recipients to a malicious link that opens a credential harvesting page on vistaipa[.]com. This page impersonates Monograph, a project management platform, displaying a fake login panel and a static dashboard image designed to steal enterprise email credentials.

Do not click links in unexpected contractor solicitations or enter your credentials on unfamiliar login pages. Always verify bidding requests through independent channels or report suspicious messages to IT Services.

Email details

Subject: [External] Contractor Bid Opportunity - New Commercial & Mixed-Use Development

You don't often get email from [name-redacted]@islandoverheaddoors[.]com. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: [Name Redacted] <[name-redacted]@islandoverheaddoors[.]com>

To: [Internal Employee]


Hello,

Our partners invite qualified contractors and vendors to submit bids for the New Commercial Development - Buildings A, B & C.

Project Size:
• Building A: 450,862.43 sq. ft.
• Building B: 450,862.43 sq. ft.
• Building C: 1,200,300.89 sq. ft.

The project includes a multi-purpose arena, conference centre, office and residential towers, retail and entertainment spaces, parking facilities, and related site infrastructure.

Updated drawings, specifications, and addenda are available through:
Island Overhead Doors - New Commercial Development - Project Documents

Scope includes: demolition, concrete work, metal fabrication, carpentry, millwork, firestopping, doors and hardware, drywall, ceilings, flooring, tile, painting, washroom accessories, and related electrical/mechanical work.

Please submit your proposal in accordance with the ITB, including all assumptions, exclusions, qualifications, and alternates.

Submission Deadline: Friday, September 18, 2026, at 5:00 PM.

Thank you for your interest. We look forward to receiving your proposal.

--
Thank You,
[Name Redacted]
Island Overhead Doors (1979) Ltd.

Phishing cues

! Compromised external sender address
  • Sent from a compromised business account ([name-redacted]@islandoverheaddoors[.]com). This helps the message get past spam filters.
! Unexpected request for bids
  • Asks you to submit bids for a major construction project without any prior contact or business history.
! Fake login page (Monograph)
  • The document link leads to vistaipa[.]com. This page mimics project software to steal your login credentials.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake President's office SharePoint document sharing scam

Published: August 9, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external Microsoft 365 tenant to distribute fraudulent SharePoint file sharing notifications. The email claims that a document is shared from the Office of President Dennis Johnson and directed to all staff. The blue Open button directs recipients to a malicious external phishing page designed to harvest login credentials.

When you receive unexpected file sharing notifications claiming to originate from senior university leadership via external domains, do not click links or select Open. Verify the request directly with the sender or contact IT Services.

Email details

Subject: [External] [Name Redacted] shared "Documentations Review1" with you

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: SharePoint Online <no-reply@sharepointonline[.]com>

To: [Internal Employees]

Cc: [Name Redacted] <[name-redacted]@somaiya[.]edu>


📤

[Name Redacted] invited you to view a file

A file Shared from the Office of President Dennis Johnson at Vancouver Island University, directed to All Staff Members.

N Documentations Review1

This invite will only work for you and people with existing access.

This email is generated through somaiya[.]edu's use of Microsoft 365 and may contain content that is controlled by somaiya[.]edu.

Phishing cues

! External email banner on internal claims
  • Shows VIU's External Email warning banner. This warns you that the message came from outside VIU, even though it claims to be from the President's office.
! Compromised external tenant
  • Sent through a compromised account at somaiya[.]edu, an external school domain, to get past spam filters.
! Impersonating university leadership
  • Claims to come from VIU President Dennis Johnson to create false authority and rush you into opening the file.
! Mismatched sender identity
  • Displays SharePoint Online and references an outside user in the subject line, but claims to share an internal document.
! Vague document name
  • Uses a generic file name (Documentations Review1) with a OneNote link and no helpful details.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake equipment downsizing and estate giveaway scam

Published: August 2, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign originates from a compromised internal staff account. The attacker claims that a benefactor is giving away valuable personal equipment, including high-end instruments, cameras and laptops. To claim these items, victims are instructed to contact an external email address or phone number. The scam requires victims to pay upfront shipping fees for items that do not exist (Advance Fee Fraud). Because the email was dispatched from a legitimate internal account, it bypasses security controls.

When you receive unexpected giveaway offers or requests to pay delivery fees, do not contact the external addresses or send money. Verify suspicious announcements directly with IT Services.

Email details

Subject: (No Subject / Blank)

From: [Internal Instructor]

To: [Internal Students and Staff]

Date: Sunday, August 2, 2026 9:44:23 PM


Dear Students and staffs,

As the academic session About to resumes, we continue to explore practical ways to support learning, research, and creative work among staffs and students.

We would like to inform you of an educational support initiative made available through Mrs. Kristian, who is in the process of downsizing personal equipment previously owned by her late husband. In keeping with her long-standing support for education, she has chosen to make several items available to students/staffs for academic and educational use.

The purpose of this initiative is to ensure that functional learning tools are put to continued use in coursework, research, creative projects, and other approved academic activities.

The available items include:

  • A gorgeous violin (swoon!)
  • A 2014 Yamaha baby grand piano (imagine the melodies!)
  • The iconic Eric Clapton signature 1939 Martin OOO-42 guitar (OMG!)
  • A Leica S (Typ 007) digital SLR camera (for all the memories!)
  • A PlayStation 5 (game on!)
  • An Xbox Series X – 2TB Galaxy Special Edition (level up!)
  • A 2023 14-inch MacBook Pro (work and play!)
  • An 11-inch 2023 iPad Pro (so sleek!)
  • A 2023 Apple Vision Pro (the future is here!)

Distribution will be handled on a fair and need-based basis....Students and staffs who wish to make an inquiry will take care of the delivery fee , information and contact Mrs. Kristian directly at her email only- Kristianaking20590[@]gmail[.]com, or phone text +1(804)670-6900 and her only iMessage contact rice20590[@]gmail[.]com. you can reach out to her on any of the listed contact options.

Thank you for your attention

[Internal Instructor]

[Redacted Faculty Name]

Instructor

Vancouver Island University

Phishing cues

! Compromised internal account
  • Sent from a real VIU account that was compromised. Attackers use this to bypass spam filters.
! Delivery fee advance scam
  • Offers free high-value items, but asks you to pay a delivery fee. The scammer keeps your money and sends nothing.
! High-value lure with casual hype
  • Lists expensive items like a grand piano and Vision Pro with strange hype words like "(swoon!)" and "(game on!)".
! Off-platform contact methods
  • Tells you to write to external Gmail addresses (Kristianaking20590[@]gmail[.]com) or text a phone number instead of using VIU email.
! Blank subject line and spelling errors
  • Has no subject line and contains grammar mistakes such as "session About to resumes" and "delivery fee , information".
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.

Phish: Fake University of Winnipeg document review scam

Published: July 29, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external account belonging to another Canadian university (University of Winnipeg). The email claims that a "complete document is ready" for review and includes a blue button labeled "View Details". Attackers use this campaign to execute Device Code authentication phishing attacks designed to hijack Microsoft 365 accounts and bypass 2-Step Verification (2SV).

When you receive unsolicited notifications claiming to contain confidential documents from external institutions, do not select View Details or enter authentication codes into unexpected prompts. Verify the request directly with the sender through an established communication channel.

Email details

Subject: [External] University of Winnipeg

You don't often get email from [name-redacted]@uwinnipeg[.]ca. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: [Name Redacted] <[name-redacted]@uwinnipeg[.]ca>

To: [Name Redacted] <[name-redacted]@uwinnipeg[.]ca>

University of Winnipeg

Your complete document is ready

We are pleased to inform you that the requested document is now available for review.

This important update reflects the latest information and is ready for your attention.

© 2026 University of Winnipeg

View Details

Phishing cues

! Compromised outside school account
  • Sent from a compromised email account at another school ([name-redacted]@uwinnipeg[.]ca) to slip past spam filters.
! Device code login trick
  • Asks you to select View Details. This starts a device code login trick to steal your account and bypass 2-Step Verification.
! External email and sender warnings
  • Displays VIU's External Email warning banner and a first-time sender alert, showing the email came from outside.
! Vague document lure
  • Uses generic phrases like "Your complete document is ready" without explaining what the file is or who requested it.
! Brand impersonation
  • Copies the University of Winnipeg logo and copyright text to make the fake email look official.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake Burnaby Neighbourhood House secure message notification

Published: July 29, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external email account belonging to Burnaby Neighbourhood House. The email claims that a secure email is waiting and contains a generic link labeled Click Here. Because the message originates from a compromised authentic sender, it may pass domain checks. However, the hyperlink directs recipients to a malicious external phishing portal designed to harvest credentials.

When you receive unexpected secure message alerts, do not click links. Hover over links to inspect the destination address or verify the message directly with the sender.

Email details

Subject: [External] Burnaby Neighbourhood House

You do not often get email from [name-redacted]@burnabynh[.]ca. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: [Name Redacted] <[name-redacted]@burnabynh[.]ca>

To: [Name Redacted] <[name-redacted]@burnabynh[.]ca>

Burnaby Neighbourhood House

Hi,

Burnaby Neighbourhood House. sent you a secure email

Click Here to review your message

If you need to share any additional details or follow up on this matter, please reply directly to this message or contact sender

Phishing cues

! Compromised external account
  • Sent from a real non-profit account ([name-redacted]@burnabynh[.]ca) that was compromised to bypass email filters.
! Suspicious link target
  • Hovering over the link shows an outside website (ggproducts[.]in) that has no link to the non-profit or VIU.
! External email and sender warnings
  • Shows the External Email banner and first-time sender alert, indicating an unverified outside message.
! Generic link text
  • Uses "Click Here" to hide the suspicious web link. Always hover over links to check where they go before clicking.
! Vague message and odd punctuation
  • Uses generic phrases like "sent you a secure email" with strange punctuation ("Burnaby Neighbourhood House.").
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fraudulent SharePoint file sharing notification

Published: June 23, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses automated Microsoft SharePoint file sharing notifications to trick university employees. The email claims that an updated employment policy document requires immediate review. Attackers send these messages from compromised external Microsoft 365 accounts to bypass traditional email filters.

When you receive unsolicited file sharing notices claiming to contain urgent employment policies or confidential documents, do not click the link or select Open. Verify the request directly with the sender or VIU Human Resources before interacting with shared files.

Email details

Subject: [External] KIT CLARK NOB shared "Vancouver Island University Updated Employment Policies and Required Review 2026–2027" with you

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: SharePoint Online <no-reply@sharepointonline[.]com>

Cc: KIT CLARK NOB <kitclark[.]nob[at]mu[.]edu[.]ph>

Reply to: kitclark[.]nob[at]mu[.]edu[.]ph

📤

KIT CLARK NOB shared a file with you

Action Required: Review Employment Policy Updates (2026–2027)

🔒 This link only works for the direct recipients of this message.

Open

This email is generated through Misamis University's use of Microsoft 365 and may contain content that is controlled by Misamis University.

Phishing cues

! External email banner on internal policy claims
  • Displays an External Email warning banner. Real VIU policy messages are sent internally and do not show this banner.
! External domain in Reply-To and Cc
  • The Reply-To and Cc lines show an outside school domain (mu[.]edu[.]ph) instead of a @viu.ca address.
! Compromised Microsoft 365 tenant
  • Attackers use compromised accounts from other organizations so their fake notices pass spam filters.
! False urgency and authority
  • Uses an urgent subject line ("Updated Employment Policies and Required Review") to rush you into opening the link without checking the sender.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Executive impersonation and fake overdue invoice scam

Published: June 22, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign impersonates university executive leadership to commit wire transfer invoice fraud. The email displays the display name of VIU President Dennis Johnson and forwards a fake email thread demanding immediate payment of an overdue vendor invoice totaling $76,024.24. Attackers send these messages from compromised external email domains and use look-alike addresses in the Reply-To field to intercept financial responses. University executives will never send informal, urgent email requests asking staff members to bypass standard financial controls or wire large sums of money immediately.

When you receive urgent payment requests claiming to originate from senior university leadership, do not reply, open attached invoice files or process payments. Verify the request through an established internal phone number or in person with your supervisor.

Email details

Subject: [External] Fw:Outstanding Payment for Invoice #20422285

noreply[at]lobbes[.]nl appears similar to someone who previously sent you email, but may not be that person. Learn why at https://aka.ms/LearnAboutSenderIdentification
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Dennis Johnson <noreply[at]lobbes[.]nl>

To: [Internal Employee]

Reply to: dennis[at]msgtel[.]com


Please ensure payment is made today.

Thank you,
Dennis Johnson

---------- Forwarded message ---------

From: Britney Jacob <britney[at]hmeportal[.]com>

To: Dennis Johnson

Sent: Friday, May 29, 2026, 02:35 PM

Subject: RE: Outstanding Payment for Invoice Overdue 20422285

Dear Dennis,

As discussed, please find attached the overdue invoice 20422285 for your reference. The outstanding balance of $76,024.24 remains unpaid.

To ensure uninterrupted continuation of your H & W Recreational Marketing VIP Club benefits, we kindly request that you arrange payment at your earliest convenience.

Note: Please send remittance advice to billing[at]hmeportal[.]com so that the invoice may be marked as paid.

Warm regards,
Britney Jacob | CEO | H & W Recreational Marketing

---------- Forwarded message ---------

From: Billing | H & W Recreational Marketing <billing[at]hmeportal[.]com>

Sent: Monday, May 4, 2026 11.42 AM

Subject: Executive Advisory Membership Service - Elevate your Team's Success

Please find attached the outstanding invoice for Advisory services rendered. Wire transfer is our preferred method of payment. Amount: $76,024.24

📎 Attachment: invoice_[Internal Employee].pdf (79.0 KB)

Phishing cues

! Impersonating university leadership
  • Displays the name of VIU President Dennis Johnson, but the sender address is a Dutch domain (noreply[@]lobbes[.]nl) and replies go to dennis[@]msgtel[.]com.
! Urgent high-dollar demand
  • Demands immediate payment ("Please ensure payment is made today") for a large sum ($76,024.24) by wire transfer.
! Fake forwarded email history
  • Includes fake email history to make it look like university leadership already approved the invoice.
! Targeted attachment
  • Includes an attached PDF (invoice_[Internal Employee].pdf) named with the recipient's name to trick them into opening it.
! External email banner
  • Shows VIU's External Email warning banner, confirming the message came from outside VIU.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake construction project subcontractor inquiry

Published: June 21, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign uses initial reconnaissance tactics to target university staff members. The email pretends to be an inquiry from a construction management company looking for subcontractors for an upcoming project. Attackers send these low-urgency inquiries to identify active email addresses and find the correct contact before sending malicious attachments or fraudulent payment requests.

When you receive unexpected vendor inquiries or request-for-proposal (RFP) solicitations from unfamiliar senders, verify the sender details and domain names before responding. Do not forward business inquiries or internal directory information to unverified external senders.

Email details

Subject: [External] Inquiry for Upcoming Construction Project: 90_Eq_90_AhQ

You do not often get email from customercare[at]netgeeks[.]net.
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Adam Smith <customercare[at]netgeeks[.]net>

To: [Internal Employee]

Reply to: Adam[.]Smith[at]whitingturner-group[.]com


Dear Team,

I hope you are doing well.

We are currently identifying subcontractors for an upcoming construction project and would like to confirm the appropriate contact for RFP or prequalification inquiries.

If you are the correct point of contact, we would be pleased to provide additional project information and discuss potential participation. If not, we would appreciate it if you could direct us to the appropriate individual or department.

Thank you for your time and assistance. We look forward to your response.

Best regards,

Adam Smith

Senior Project Manager

Whiting-Turner

T: +1 425 386 9804

E: Adam[.]Smith[at]whitingturner-group[.]com

W: www.whiting-turner.com

Phishing cues

! Mismatched sender and Reply-To addresses
  • Sent from customercare[@]netgeeks[.]net, but replies and the signature point to [name-redacted][@]whitingturner-group[.]com.
! Look-alike fake domain
  • The real company site is whiting-turner[.]com, but the email uses a fake domain (whitingturner-group[.]com).
! Checking if your email is active
  • Uses a polite business question to see if your inbox is active and collect staff names before sending more dangerous scams.
! Random tracking code in subject
  • Adds random characters (90_Eq_90_AhQ) to the subject line to trick spam filters.
! Generic greeting
  • Uses a generic greeting ("Dear Team,") instead of addressing you by name.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake device compatibility alert

Published: June 19, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign uses survey platforms to send fake technical security alerts to university staff. The message claims that a critical firmware conflict is blocking your device from receiving essential security updates and demands immediate manual intervention. Attackers send these emails via SurveyMonkey to bypass email filters and trick users into clicking malicious software update links. VIU IT Services does not send hardware or firmware security alerts through third-party survey services like SurveyMonkey.

When you receive unexpected technical notices asking you to update firmware or software, do not click Update Now. Report the message to IT Services immediately.

Email details

Subject: [External] Device Compatibility Alert - Action Required

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: notice[at]priority[.]notification[.]mail via SurveyMonkey <member@surveymonkeyuser.com>

To: [Internal Employee]

Reply to: notice[at]priority[.]notification[.]mail


Dear [Internal Employee],

We've uncovered a critical firmware conflict that's blocking your device from receiving essential security enhancements. Your hardware remains secure at this moment, but continued access is not guaranteed unless you take action.

This isn't a routine suggestion—it's a required manual intervention to restore full functionality and protect your assets from potential disruption.

Update Now

Thank you for acting quickly to keep your device secure and fully operational.

⚪ Sincerely,

Please do not forward this email as its survey link is unique to you.

Privacy | Unsubscribe

Powered by SurveyMonkey

Phishing cues

! Abuse of survey platforms (SurveyMonkey)
  • Sent using SurveyMonkey (member[@]surveymonkeyuser[.]com) to slip past spam filters. IT Services never sends hardware warnings through survey tools.
! Survey footer reveals true origin
  • The footer says "Please do not forward this email as its survey link is unique to you", proving this is a survey form rather than an IT alert.
! Misleading display name
  • Uses a fake sender name (notice[@]priority[.]notification[.]mail) to pretend to be an official automated IT system.
! Scare tactics and technical jargon
  • Uses alarming terms like "critical firmware conflict" to cause panic and rush you into clicking.
! External email banner on internal claims
  • Shows VIU's External Email warning banner. Real IT maintenance notices come from internal @viu.ca addresses.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake Canada Revenue Agency tax notice

Published: June 6, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign targets university students and staff by impersonating the Canada Revenue Agency (CRA). The email claims that an updated 2025 T4 tax document is available for viewing and requires immediate attention. Attackers send these messages from fraudulent external email addresses to steal personal information and banking login credentials. Government agencies such as the CRA do not send email notifications containing direct links to log in or download tax forms.

When you receive tax-related notifications, do not click embedded links or select Click Here. Access your CRA My Account safely by typing the official website URL directly into your web browser.

Email details

Subject: [External] File Status Update - Transfer Request - Canada Revenue Agency / Mise à jour sur l'état des dossiers - Demande de transfert - Agence du revenu du Canada [Ref: 3B1A7]

You do not often get email from ventas[at]aimeos[.]masiva[.]red.
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Canada Revenue Agency (MyCRA) <ventas[at]aimeos[.]masiva[.]red>

To: [Internal Student]

Reply to: Canada Revenue Agency (MyCRA)


English version *** La version française suit ***

There is unread mail with an updated 2025 T4 from the Canada Revenue Agency (CRA) dated June 04, 2026, in your My Account, that requires your attention.

Click Here to view "Mail/PDF Attached" to read your mail.

If you do not have My Account, go to the CRA website to register.

This is an automated email message UW5UWR7K. Please do not reply.

Version française *** The English version precedes ***

Phishing cues

! Government agency impersonation (CRA)
  • Claims to come from the Canada Revenue Agency about a T4 tax slip. The CRA never emails direct links to access tax records.
! Suspicious sender address
  • Sent from an outside domain (attacker[@]tax-notice-portal[.]com) that has no link to the Canadian government.
! Fake login link
  • The link directs you to an external website designed to steal your CRA or banking credentials.
! External email banner
  • Displays VIU's External Email warning banner, confirming the message was sent from outside the university.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.