Search button
  • About McMaster
    • Home
    • News
    • Research & Innovation
    • Giving to McMaster
    • Working at McMaster
  • Study
    • Undergraduate Programs
    • Graduate Programs
    • Continuing Education
    • Admission Requirements
  • Visit
    • Tours
    • Campus Maps
    • Campus Safety Services
    • Events
  • Connect
    • University Directories
    • Media Inquiries
    • Research Centres & Institutes
    • McMaster Global
    • Alumni

Student Support

  • Campus Safety Services
  • Equity & Inclusion Office
  • IT Support
  • Office of the Registrar
  • Ombuds Office
  • School of Graduate Studies
  • Student Wellness Centre
  • Student Affairs

Tools

  • Academic Calendars
  • Avenue to Learn
  • Campus Maps
  • Faculty and Staff Directory
  • Find an Expert
  • Microsoft Office 365
  • Mosaic
  • Safety App

Faculties

  • DeGroote School of Business
  • Engineering
  • Health Sciences
  • Humanities
  • Science
  • Social Sciences

On Campus

  • Athletics & Recreation
  • Campus Store
  • Housing & Conference Services
  • Hospitality Services
  • Libraries
  • Student Success Centre
McMaster University McMaster logo

Office of the AVP & CTO

  • Home
  • People
  • Policy
  • Procedures
  • Standards
  • Resources
  • Contacts
  1. Home
  2. Security Notice – Increase in Phishing Attacks Targeting the McMaster Community

Security Notice – Increase in Phishing Attacks Targeting the McMaster Community

Posted on April 24, 2026
Twitter Facebook LinkedIn

The Security Operations team has observed a recent increase in phishing attacks targeting the McMaster community. 

In many cases, these attacks use compromised email accounts and fraudulent websites that imitate legitimate McMaster or Microsoft login pages. These fake login pages are designed to capture usernames, passwords, and session tokens. This can allow attackers to access accounts until a re-authentication or step-up authentication prompt is triggered. 

The following example shows a phishing page impersonating a McMaster-branded login portal. 

Attackers may also mimic commonly used services such as Microsoft 365 to make these pages appear more legitimate, as shown in the example below. 

Some phishing pages go further and request additional personal information beyond just a username and password, as demonstrated here. 

The Security Operations team is advising the McMaster community to verify any login page before entering credentials. Always check the URL, avoid clicking links in unsolicited emails, and access McMaster services through trusted bookmarks or the main website. 

If you encounter a suspicious message or believe you may have entered your credentials on a phishing site, please report it immediately to is-spam@mcmaster.ca. 

 Phish Bowl

Related News

News Listing

Phishing Scam: Phone Call

Phish Bowl

June 26, 2026

IT Notice – Increase in ClickFix Social Engineering Attacks

Phish Bowl

March 13, 2026

Phishing Email Scam: Held Message Notice

Phish Bowl

February 27, 2026

Office of the AVP & CTO

TwitterInstagram

Policies

Information Security Policy
Information Storage Guidelines
Mac ID Terms and Conditions of Use

Support & Contact

Report an incident
Contact us

Accessibility

McMaster University is committed to providing websites that are accessible to the widest possible audience. If you require any content on this website in an alternate format, please contact the UTS Service Desk and we will respond as promptly as possible.

If there is an AODA web accessibility issue with this website, please report it to Media Production Services using our AODA bug reporting form.

This website is powered by MacSites

McMaster logo
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • 1280 Main Street West  Hamilton, Ontario  L8S 4L8
  • (905) 525-9140

© 2026 McMaster University