Phish Bowl

Summary

Phish Bowl Blog to document recent phishing emails

Body

Welcome to the Phish Bowl

This page is a blog-style list of recent phishing attempts that our Information Security team has identified. Entries are organized below by "most recent." This will allow users to get a peek at how attempts to compromise VIU's information security will present themselves in your Inbox.

If you are ever find yourself on the receiving end of something that seems "phish-y" to you, the examples below can help you to know for sure, so check back often. If you're still unsure, use the Report phishing links at the bottom of each entry. 


Phish: Fake President's office SharePoint document sharing scam

Published: August 9, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external Microsoft 365 tenant to distribute fraudulent SharePoint file sharing notifications. The email claims that a document is shared from the Office of President Dennis Johnson and directed to all staff. The blue Open button directs recipients to a malicious external phishing page designed to harvest login credentials.

When you receive unexpected file sharing notifications claiming to originate from senior university leadership via external domains, do not click links or select Open. Verify the request directly with the sender or contact IT Services.

Email details

Subject: [External] [Name Redacted] shared "Documentations Review1" with you

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: SharePoint Online <no-reply@sharepointonline[.]com>

To: [Internal Employees]

Cc: [Name Redacted] <[name-redacted]@somaiya[.]edu>


📤

[Name Redacted] invited you to view a file

A file Shared from the Office of President Dennis Johnson at Vancouver Island University, directed to All Staff Members.

N Documentations Review1

This invite will only work for you and people with existing access.

This email is generated through somaiya[.]edu's use of Microsoft 365 and may contain content that is controlled by somaiya[.]edu.

Phishing cues

! External email banner on internal claims
  • Displays VIU's External Email warning banner, which contradicts the claim that the file is shared from the internal Office of President Dennis Johnson.
! Compromised external tenant (somaiya[.]edu)
  • Sent through a compromised external Microsoft 365 tenant (somaiya[.]edu) belonging to an external organisation, bypassing basic domain validation checks.
! Executive impersonation
  • Pretends to originate from VIU President Dennis Johnson to create a false sense of authority and pressure recipients into opening the document.
! Mismatched sender identity
  • Lists the display name as SharePoint Online and references a compromised user in the subject line, but claims the document belongs to the President's office.
! Vague document name and lack of context
  • Uses a generic file name (Documentations Review1) with a OneNote link and no prior business context or explanation.
! Grammatical and formatting anomalies
  • Features capitalization errors ("A file Shared from...") and awkward phrasing ("directed to All Staff Members.").
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake equipment downsizing and estate giveaway scam

Published: August 2, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign originates from a compromised internal staff account. The attacker claims that a benefactor is giving away valuable personal equipment, including high-end instruments, cameras and laptops. To claim these items, victims are instructed to contact an external email address or phone number. The scam requires victims to pay upfront shipping fees for items that do not exist (Advance Fee Fraud). Because the email was dispatched from a legitimate internal account, it bypasses security controls.

When you receive unexpected giveaway offers or requests to pay delivery fees, do not contact the external addresses or send money. Verify suspicious announcements directly with IT Services.

Email details

Subject: (No Subject / Blank)

From: [Internal Instructor]

To: [Internal Students and Staff]

Date: Sunday, August 2, 2026 9:44:23 PM


Dear Students and staffs,

As the academic session About to resumes, we continue to explore practical ways to support learning, research, and creative work among staffs and students.

We would like to inform you of an educational support initiative made available through Mrs. Kristian, who is in the process of downsizing personal equipment previously owned by her late husband. In keeping with her long-standing support for education, she has chosen to make several items available to students/staffs for academic and educational use.

The purpose of this initiative is to ensure that functional learning tools are put to continued use in coursework, research, creative projects, and other approved academic activities.

The available items include:

  • A gorgeous violin (swoon!)
  • A 2014 Yamaha baby grand piano (imagine the melodies!)
  • The iconic Eric Clapton signature 1939 Martin OOO-42 guitar (OMG!)
  • A Leica S (Typ 007) digital SLR camera (for all the memories!)
  • A PlayStation 5 (game on!)
  • An Xbox Series X – 2TB Galaxy Special Edition (level up!)
  • A 2023 14-inch MacBook Pro (work and play!)
  • An 11-inch 2023 iPad Pro (so sleek!)
  • A 2023 Apple Vision Pro (the future is here!)

Distribution will be handled on a fair and need-based basis....Students and staffs who wish to make an inquiry will take care of the delivery fee , information and contact Mrs. Kristian directly at her email only- Kristianaking20590[@]gmail[.]com, or phone text +1(804)670-6900 and her only iMessage contact rice20590[@]gmail[.]com. you can reach out to her on any of the listed contact options.

Thank you for your attention

[Internal Instructor]

[Redacted Faculty Name]

Instructor

Vancouver Island University

Phishing cues

! Compromised internal account
  • The email was sent from an active internal university account to bypass external spam filters and domain validation (SPF/DKIM/DMARC).
! Advance-fee / delivery fee fraud lure
  • Promises free expensive equipment but demands that interested victims "take care of the delivery fee". Money sent for shipping goes directly to scammers and no items are delivered.
! High-value lure with informal exclamations
  • Lists high-ticket items (baby grand piano, Martin guitar, Leica camera, Vision Pro) paired with odd parenthetical notes ("(swoon!)", "(OMG!)", "(game on!)") to spark impulsive responses.
! Off-platform webmail, SMS & iMessage contact
  • Instructs recipients to communicate outside VIU channels via external Gmail addresses (Kristianaking20590[@]gmail[.]com, rice20590[@]gmail[.]com) or text message (+1(804)670-6900).
! Blank subject line & grammatical errors
  • Contains no subject line and multiple grammatical mistakes ("session About to resumes", "staffs", "delivery fee , information").
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.

Phish: Fake University of Winnipeg document review scam

Published: July 29, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external account belonging to another Canadian university (University of Winnipeg). The email claims that a "complete document is ready" for review and includes a blue button labeled "View Details". Attackers use this campaign to execute Device Code authentication phishing attacks designed to hijack Microsoft 365 accounts and bypass 2-Step Verification (2SV).

When you receive unsolicited notifications claiming to contain confidential documents from external institutions, do not select View Details or enter authentication codes into unexpected prompts. Verify the request directly with the sender through an established communication channel.

Email details

Subject: [External] University of Winnipeg

You don't often get email from [name-redacted]@uwinnipeg[.]ca. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: [Name Redacted] <[name-redacted]@uwinnipeg[.]ca>

To: [Name Redacted] <[name-redacted]@uwinnipeg[.]ca>

University of Winnipeg

Your complete document is ready

We are pleased to inform you that the requested document is now available for review.

This important update reflects the latest information and is ready for your attention.

© 2026 University of Winnipeg

View Details

Phishing cues

! Compromised external university account
  • Sent from a compromised external university email account ([name-redacted]@uwinnipeg[.]ca) to bypass basic email filters.
! Device Code authentication phishing tactic
  • Prompts the recipient to select View Details, initiating a Device Code authentication flow to compromise Microsoft 365 accounts and bypass 2-Step Verification (2SV).
! External email and first-time sender warnings
  • Displays VIU's External Email banner alongside Outlook's first-time sender warning, confirming the email did not originate internally.
! Generic document lure
  • Uses vague statements ("Your complete document is ready", "reflects the latest information") without explaining what document is being shared or who requested it.
! Brand impersonation
  • Uses University of Winnipeg logo branding and copyright notices to create false legitimacy for an unverified external message.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake Burnaby Neighbourhood House secure message notification

Published: July 29, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses a compromised external email account belonging to Burnaby Neighbourhood House. The email claims that a secure email is waiting and contains a generic link labeled Click Here. Because the message originates from a compromised authentic sender, it may pass domain checks. However, the hyperlink directs recipients to a malicious external phishing portal designed to harvest credentials.

When you receive unexpected secure message alerts, do not click links. Hover over links to inspect the destination address or verify the message directly with the sender.

Email details

Subject: [External] Burnaby Neighbourhood House

You do not often get email from [name-redacted]@burnabynh[.]ca. Learn why this is important
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: [Name Redacted] <[name-redacted]@burnabynh[.]ca>

To: [Name Redacted] <[name-redacted]@burnabynh[.]ca>

Burnaby Neighbourhood House

Hi,

Burnaby Neighbourhood House. sent you a secure email

Click Here to review your message

If you need to share any additional details or follow up on this matter, please reply directly to this message or contact sender

Phishing cues

! Compromised external sender account
  • The email was sent from a legitimate non-profit organisation account ([name-redacted]@burnabynh[.]ca) that was compromised by attackers to bypass email filters.
! Suspicious external link destination
  • Hovering over the link reveals an external credential harvesting website (ggproducts[.]in) that has no connection to Burnaby Neighbourhood House or VIU.
! External email and first-time sender warnings
  • The message displays an External Email warning banner alongside Outlook's first-time sender alert, indicating an unverified external communication.
! Generic hyperlinked text ("Click Here")
  • Uses non-descriptive link text ("Click Here") to obscure the malicious destination URL. Always hover over links to inspect the full web address before clicking.
! Vague lure and punctuation errors
  • Uses generic language ("sent you a secure email") and improper punctuation ("Burnaby Neighbourhood House.") without explaining what document is being shared.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fraudulent SharePoint file sharing notification

Published: June 23, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign abuses automated Microsoft SharePoint file sharing notifications to trick university employees. The email claims that an updated employment policy document requires immediate review. Attackers send these messages from compromised external Microsoft 365 accounts to bypass traditional email filters.

When you receive unsolicited file sharing notices claiming to contain urgent employment policies or confidential documents, do not click the link or select Open. Verify the request directly with the sender or VIU Human Resources before interacting with shared files.

Email details

Subject: [External] KIT CLARK NOB shared "Vancouver Island University Updated Employment Policies and Required Review 2026–2027" with you

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: SharePoint Online <no-reply@sharepointonline[.]com>

Cc: KIT CLARK NOB <kitclark[.]nob[at]mu[.]edu[.]ph>

Reply to: kitclark[.]nob[at]mu[.]edu[.]ph

📤

KIT CLARK NOB shared a file with you

Action Required: Review Employment Policy Updates (2026–2027)

🔒 This link only works for the direct recipients of this message.

Open

This email is generated through Misamis University's use of Microsoft 365 and may contain content that is controlled by Misamis University.

Phishing cues

! External email banner on internal policy claims
  • The email displays an External Email warning banner. Authentic VIU employment policy communications originate internally without external warnings.
! External domain in Reply-To and Cc
  • The Cc and Reply-To headers reference an external university domain (mu[.]edu[.]ph - Misamis University) rather than a @viu.ca address.
! Abuse of legitimate Microsoft 365 tenant
  • Attackers compromise third-party Microsoft 365 tenants to send legitimate SharePoint notices that evade spam filters.
! Sense of urgency and authority impersonation
  • Uses official-sounding titles ("Updated Employment Policies and Required Review") to pressure recipients into opening the document without verifying the sender.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Executive impersonation and fake overdue invoice scam

Published: June 22, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign impersonates university executive leadership to commit wire transfer invoice fraud. The email displays the display name of VIU President Dennis Johnson and forwards a fake email thread demanding immediate payment of an overdue vendor invoice totaling $76,024.24. Attackers send these messages from compromised external email domains and use look-alike addresses in the Reply-To field to intercept financial responses. University executives will never send informal, urgent email requests asking staff members to bypass standard financial controls or wire large sums of money immediately.

When you receive urgent payment requests claiming to originate from senior university leadership, do not reply, open attached invoice files or process payments. Verify the request through an established internal phone number or in person with your supervisor.

Email details

Subject: [External] Fw:Outstanding Payment for Invoice #20422285

noreply[at]lobbes[.]nl appears similar to someone who previously sent you email, but may not be that person. Learn why at https://aka.ms/LearnAboutSenderIdentification
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Dennis Johnson <noreply[at]lobbes[.]nl>

To: [Internal Employee]

Reply to: dennis[at]msgtel[.]com


Please ensure payment is made today.

Thank you,
Dennis Johnson

---------- Forwarded message ---------

From: Britney Jacob <britney[at]hmeportal[.]com>

To: Dennis Johnson

Sent: Friday, May 29, 2026, 02:35 PM

Subject: RE: Outstanding Payment for Invoice Overdue 20422285

Dear Dennis,

As discussed, please find attached the overdue invoice 20422285 for your reference. The outstanding balance of $76,024.24 remains unpaid.

To ensure uninterrupted continuation of your H & W Recreational Marketing VIP Club benefits, we kindly request that you arrange payment at your earliest convenience.

Note: Please send remittance advice to billing[at]hmeportal[.]com so that the invoice may be marked as paid.

Warm regards,
Britney Jacob | CEO | H & W Recreational Marketing

---------- Forwarded message ---------

From: Billing | H & W Recreational Marketing <billing[at]hmeportal[.]com>

Sent: Monday, May 4, 2026 11.42 AM

Subject: Executive Advisory Membership Service - Elevate your Team's Success

Please find attached the outstanding invoice for Advisory services rendered. Wire transfer is our preferred method of payment. Amount: $76,024.24

📎 Attachment: invoice_[Internal Employee].pdf (79.0 KB)

Phishing cues

! Executive impersonation (President / CEO fraud)
  • Displays the display name of VIU President Dennis Johnson, but the sender email address (noreply[at]lobbes[.]nl) is an external Dutch domain, and the Reply-To address points to dennis[at]msgtel[.]com.
! Urgent high-value financial demand
  • Demands immediate payment ("Please ensure payment is made today") for a large overdue balance ($76,024.24) using wire transfer.
! Fabricated forwarded email thread
  • Uses fake forwarded email headers to create artificial credibility and give the illusion that the President previously discussed and approved the payment.
! Targeted malicious PDF attachment
  • Contains an attached PDF file (invoice_[Internal Employee].pdf) customized with the recipient's name to trick them into opening a malicious payload.
! External email banner and sender warning
  • Displays VIU's External Email banner alongside Outlook's sender identification alert, confirming the email did not originate internally.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake construction project subcontractor inquiry

Published: June 21, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign uses initial reconnaissance tactics to target university staff members. The email pretends to be an inquiry from a construction management company looking for subcontractors for an upcoming project. Attackers send these low-urgency inquiries to identify active email addresses and find the correct contact before sending malicious attachments or fraudulent payment requests.

When you receive unexpected vendor inquiries or request-for-proposal (RFP) solicitations from unfamiliar senders, verify the sender details and domain names before responding. Do not forward business inquiries or internal directory information to unverified external senders.

Email details

Subject: [External] Inquiry for Upcoming Construction Project: 90_Eq_90_AhQ

You do not often get email from customercare[at]netgeeks[.]net.
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Adam Smith <customercare[at]netgeeks[.]net>

To: [Internal Employee]

Reply to: Adam[.]Smith[at]whitingturner-group[.]com


Dear Team,

I hope you are doing well.

We are currently identifying subcontractors for an upcoming construction project and would like to confirm the appropriate contact for RFP or prequalification inquiries.

If you are the correct point of contact, we would be pleased to provide additional project information and discuss potential participation. If not, we would appreciate it if you could direct us to the appropriate individual or department.

Thank you for your time and assistance. We look forward to your response.

Best regards,

Adam Smith

Senior Project Manager

Whiting-Turner

T: +1 425 386 9804

E: Adam[.]Smith[at]whitingturner-group[.]com

W: www.whiting-turner.com

Phishing cues

! Sender address vs Reply-To header mismatch
  • The email was sent from customercare[at]netgeeks[.]net, but the Reply-To header and email signature point to Adam[.]Smith[at]whitingturner-group[.]com.
! Domain typosquatting and impersonation
  • The legitimate company website listed in the signature is whiting-turner.com, but the Reply-To domain uses a look-alike fake domain (whitingturner-group[.]com).
! Initial reconnaissance tactic
  • Uses a polite business inquiry ("identifying subcontractors for an upcoming construction project") to test if an account is active and find department contacts before delivering secondary attacks.
! Randomized tracking code in subject line
  • Includes a random string (90_Eq_90_AhQ) in the subject line, which automated spam tools use to bypass email filters.
! Generic greeting
  • Addresses the recipient with a generic greeting ("Dear Team,") rather than using their name.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake device compatibility alert

Published: June 19, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign uses survey platforms to send fake technical security alerts to university staff. The message claims that a critical firmware conflict is blocking your device from receiving essential security updates and demands immediate manual intervention. Attackers send these emails via SurveyMonkey to bypass email filters and trick users into clicking malicious software update links. VIU IT Services does not send hardware or firmware security alerts through third-party survey services like SurveyMonkey.

When you receive unexpected technical notices asking you to update firmware or software, do not click Update Now. Report the message to IT Services immediately.

Email details

Subject: [External] Device Compatibility Alert - Action Required

External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: notice[at]priority[.]notification[.]mail via SurveyMonkey <member@surveymonkeyuser.com>

To: [Internal Employee]

Reply to: notice[at]priority[.]notification[.]mail


Dear [Internal Employee],

We've uncovered a critical firmware conflict that's blocking your device from receiving essential security enhancements. Your hardware remains secure at this moment, but continued access is not guaranteed unless you take action.

This isn't a routine suggestion—it's a required manual intervention to restore full functionality and protect your assets from potential disruption.

Update Now

Thank you for acting quickly to keep your device secure and fully operational.

⚪ Sincerely,

Please do not forward this email as its survey link is unique to you.

Privacy | Unsubscribe

Powered by SurveyMonkey

Phishing cues

! Abuse of third-party survey platforms (SurveyMonkey)
  • Sent using SurveyMonkey (member@surveymonkeyuser.com) to bypass email filters. IT Services does not distribute hardware security alerts through survey tools.
! Survey footer discloses true email origin
  • The email footer explicitly states "Please do not forward this email as its survey link is unique to you" alongside Privacy | Unsubscribe links, revealing that the security alert is actually a survey link.
! Misleading display name and Reply-To headers
  • Uses an official-sounding display name (notice[at]priority[.]notification[.]mail) to pretend to be an automated IT system.
! Fear-mongering and technical jargon
  • Uses intimidating language ("critical firmware conflict", "protect your assets from potential disruption") to create artificial urgency and panic.
! Generic greeting using email address
  • Addresses the recipient using their raw email address (Dear [Internal Employee],) instead of their full name.
! External email banner on internal system claims
  • Displays VIU's External Email warning banner. Authentic IT system maintenance messages originate internally from @viu.ca addresses.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.


Phish: Fake Canada Revenue Agency tax notice

Published: June 6, 2026  |  Category: Security Awareness PhishBowl

This phishing campaign targets university students and staff by impersonating the Canada Revenue Agency (CRA). The email claims that an updated 2025 T4 tax document is available for viewing and requires immediate attention. Attackers send these messages from fraudulent external email addresses to steal personal information and banking login credentials. Government agencies such as the CRA do not send email notifications containing direct links to log in or download tax forms.

When you receive tax-related notifications, do not click embedded links or select Click Here. Access your CRA My Account safely by typing the official website URL directly into your web browser.

Email details

Subject: [External] File Status Update - Transfer Request - Canada Revenue Agency / Mise à jour sur l'état des dossiers - Demande de transfert - Agence du revenu du Canada [Ref: 3B1A7]

You do not often get email from ventas[at]aimeos[.]masiva[.]red.
External Email: This email was sent from outside VIU. Treat links and attachments with extra caution.

From: Canada Revenue Agency (MyCRA) <ventas[at]aimeos[.]masiva[.]red>

To: [Internal Student]

Reply to: Canada Revenue Agency (MyCRA)


English version *** La version française suit ***

There is unread mail with an updated 2025 T4 from the Canada Revenue Agency (CRA) dated June 04, 2026, in your My Account, that requires your attention.

Click Here to view "Mail/PDF Attached" to read your mail.

If you do not have My Account, go to the CRA website to register.

This is an automated email message UW5UWR7K. Please do not reply.

Version française *** The English version precedes ***

Phishing cues

! Impersonates a government agency (CRA)
  • Claims to originate from the Canada Revenue Agency regarding a T4 tax slip. The CRA never sends emails with direct links to access tax documents.
! Suspicious sender email address
  • The sender address (ventas[at]aimeos[.]masiva[.]red) has no connection to official Government of Canada domains (canada.ca or cra-arc.gc.ca).
! External email and first-time sender warnings
  • Displays Outlook's first-time sender notice alongside VIU's External Email warning banner.
! Generic hyperlinked text ("Click Here")
  • Uses non-descriptive link text ("Click Here") to obscure a malicious credential harvesting website. Always hover over links to inspect the destination URL.
⚠️

Report phishing

If you receive a suspicious email, do not open attachments or click on links. Use Report Phishing in Outlook as the preferred method, or contact IT Services to provide the attachment.

Details

Details

Article ID: 15629
Created
Tue 7/28/26 3:15 PM
Modified
Mon 8/17/26 12:07 PM