The Security Operations team has observed a recent increase in phishing attacks targeting the McMaster community.
In many cases, these attacks use compromised email accounts and fraudulent websites that imitate legitimate McMaster or Microsoft login pages. These fake login pages are designed to capture usernames, passwords, and session tokens. This can allow attackers to access accounts until a re-authentication or step-up authentication prompt is triggered.
The following example shows a phishing page impersonating a McMaster-branded login portal.
Attackers may also mimic commonly used services such as Microsoft 365 to make these pages appear more legitimate, as shown in the example below.
Some phishing pages go further and request additional personal information beyond just a username and password, as demonstrated here.
The Security Operations team is advising the McMaster community to verify any login page before entering credentials. Always check the URL, avoid clicking links in unsolicited emails, and access McMaster services through trusted bookmarks or the main website.
If you encounter a suspicious message or believe you may have entered your credentials on a phishing site, please report it immediately to is-spam@mcmaster.ca.
Phish Bowl