Phishing emails & Banner for External Emails

Update #1

CIS has confirmed that one or more phishing emails were received by recipients in the Central Office and at some CUNY campuses from a compromised CUNY email account. While CIS continues its investigation, containment, and remediation activities, please review the following information and take action as appropriate.

Security threat Identification/symptoms

A phishing email with the subject of “School IT Notification.” There may be other versions. Do NOT click or respond to the fraudulent request within the message.

If you think you have already been impacted by this security threat

If you received this message or one like it, delete it and do not respond or reply to the message. If you already responded to the phishing email, immediately contact the Technology HelpDesk (xHELP).

Recommended User Action

  • DO NOT reply to unexpected or unusual emails from any sender.
  • DO be particularly cautious when the “external source” warning banner is present. 
  • DO NOT reply to email with any personal information or passwords. If you have reason to believe that the request is real, call the institution or company directly.
  • DO NOT click a link or open an attachment in an unsolicited email message. If you have reason to believe the request is real, type the Web address for the company or institution directly into your Web browser.
  • DO NOT use the same password for your work account, bank, Facebook, etc. In the event you do fall victim to a phishing attempt, perpetrators attempt to use your compromised password to access many online services.
  • DO change ALL of your passwords if you suspect any account to which you have access may be compromised.
  • DO be particularly cautious when reading email on a mobile device. It may be easier to miss telltale signs of phishing attempts when reading email on a smaller screen.
  • DO remember that official communications should not solicit personal information by email.
  • DO read the CUNY Phishing Advisory posted at security.cuny.edu under CUNY Issued Security Advisories.
  • DO complete information security awareness training located at security.cuny.edu.

Security Alert Updates

CIS will send an update if/when there is more information to share.

By CSI Technology Services