Don鈥檛 Fall for the Phish: Spotting Fake Logins Before It鈥檚 Too Late
Posted in: News
Phishing attacks are getting sneakier鈥攁nd more convincing. One of the most common tricks we鈥檙e seeing is fake login pages designed to mimic 星空无限传媒 University鈥檚 single sign-on (SSO) system. These pages often look identical to the real thing but are designed to steal your login credentials 鈥 and even your Duo codes.
Whether you’re a student, faculty member, or staff, it’s important to stay alert. Here’s how to spot a fake, what to do if something feels off, and what to do if you鈥檝e already clicked.
How to Spot a Phishing Email
Phishing emails try to trick you into clicking a link or downloading an attachment. Look for these red flags:
-
Urgency or threats: 鈥淵our account will be deactivated in 24 hours!鈥
-
Unusual sender address: The display name might look legit, but the actual email address is off.
-
Generic greetings: 鈥淒ear user鈥 instead of your name.
-
Strange formatting or logos: Low-quality images, misspelled words, weird spacing.
-
Unexpected attachments or links: Especially if you weren鈥檛 expecting anything.
Hover Before You Click
Before you click any link, hover your mouse over it (or long-press on mobile) to see where it actually goes.
Ask yourself:
-
Does the URL match the real login domain?
-
Is it spelled correctly? (e.g.
montclair.eduvs.montclalr.edu) -
Does it use HTTPS (a padlock icon 馃敀 in the address bar)?
Fake SSO login pages often look identical to the real thing, but the URL will usually give them away.
Trust Your Gut 鈥 and Double Check
If something feels off, don鈥檛 click! Instead:
-
Open a new browser tab and go directly to your usual login page 鈥 don鈥檛 use the link in the email.
-
Contact IT Service Desk if you鈥檙e unsure.
-
Report it using the Phishing Alert Button (PAB) or by forwarding it to phishfiles@montclair.edu.
Extra Protection: MFA & Duo Security Tips
Don鈥檛 Approve Unexpected Duo Pushes
If you get a Duo request and you鈥檙e not actively logging in, don鈥檛 tap approve 鈥 that鈥檚 a red flag that someone may have your password and is trying to access your account.
Never Share Your Duo Codes
Some phishing scams ask you to enter or send a Duo code. Just like your password, your Duo codes are private 鈥 no one, including IT, will ever ask for them.
Know About MFA Fatigue
MFA fatigue is when an attacker spams your Duo app with repeated login requests, hoping you鈥檒l approve one just to make it stop. If that happens:
-
Don鈥檛 approve any requests.
-
Report it to IT right away.
-
Change your password immediately.
MFA works only when you鈥檙e in control. If something feels off, trust your instincts and act fast.
What to Do If You Clicked or Entered Info
If you accidentally submitted your login credentials on a fake page:
-
Change your password(s) immediately 鈥 Start with your . If you use a similar password anywhere else (including personal accounts) reset those as well!
-
Notify the Phish Files 鈥 Use the Knowbe4 PAB or forward the email to phishfiles@montclair.edu.
-
Stay alert for Duo requests 鈥 If you see any suspicious ones, don鈥檛 approve them.
-
Monitor your account 鈥 Look for unusual activity (like login attempts from unfamiliar locations).
How to Report Phishing
If you get a suspicious email:
-
Don鈥檛 click anything.
- Use the Knowbe4 PAB
-
Forward it to phishfiles@montclair.edu.
TL;DR 鈥 Quick Safety Tips
-
Hover over links before clicking.
-
Always check the URL on login pages.
-
Don鈥檛 trust emails that rush you or threaten action.
-
Never approve unexpected Duo requests or share MFA codes.
-
Report anything suspicious.
-
If you鈥檙e not sure 鈥 ask IT!
- Email:itservicedesk@montclair.edu
- Call: 973-655-7971
Bonus Tip: Bookmark the Real Login Page
To avoid ever clicking a fake link, bookmark any official pages you use (like )聽and only sign in from that link. It’s a simple habit that can save you from phishing scams.
“Ask me about Duran Duran.”
鈥 Emily Harris JD, CISSP, CIPP/US
Chief Information Security Officer
Want to Know More?
FBI.gov |
ITPro |