Phishing email body:

Email Users.

This email is to notify all staff and students that active accounts are being validated.


Follow the link below to complete the verification process before deadline

 

madisoncollege.edu/e-mail-verification-process

 

IT Administrator

Annotation

About the phishing email

The phishing email highlighted in this article impersonates the Information Technology (IT) Department targeting staff and students. It urges recipients to verify their email accounts by clicking a link that appears to lead to a legitimate domain (madisoncollege.edu). While the link appears to come from a trusted domain, it is deceptive and redirects users to a fraudulent web page designed to steal login credentials. The phishing email was first observed on May 26, 2025.

Below is a list of senders and subjects related to this phishing email.

Senders:

Subjects:

  • Program Report: Action Required
  • Program Enrolment: Action Required
  • Enrolment Program: Action Required
  • Review Program: Action Required
  • Program Review: Action Required
  • Program Status: Action Required

Why This Is Dangerous

The threat actor creates a sense of urgency and authority to trick users into clicking the link and entering their credentials on a fake login page. Once entered, this information can be used to:

  • Access your email and sensitive data
  • Impersonate you to others
  • Launch further attacks within your organization

Tips on staying safe

Try these tips to protect yourself and your organization from phishing attacks:

  • Do not click on suspicious links, even if they appear to come from a familiar domain.
  • Verify the sender by checking the email address carefully.
  • Report suspicious emails to your IT department immediately.
  • Enable multi-factor authentication (MFA) to add an extra layer of security.

What to Do If You Clicked the Link

If you believe you may have interacted with the phishing email:

  1. Change your password in the Microsoft My Sign-ins portal located at https://mysignins.microsoft.com/security-info/password/change
  2. Notify the Technology Services Help Desk via email helpdesk@madisoncollege.edu or phone (608) 246-6666
  3. Monitor your account sign-ins for any unusual activity at https://mysignins.microsoft.com/