Overview
Welcome to Oakland University's Phish Tank. This page provides examples of phishing messages and is designed to spread awareness to the OU community about the numerous types of phishing attacks that exist. Malicious actors are constantly developing new methods to trick end-users into handing over sensitive information, and it's the community's mission to protect themselves by identifying these ever-evolving tactics.
To report possible phishing attempts, please visit Phishing (Phish Tank).
For general phishing information, please visit Phish Tank - Email Phishing.
Scope
Anyone with access to an active OU email address is susceptible to a phishing attack.
Fresh Phish
7/9/2026: Credential Harvest via Fake SSO Page and Fake DUO Request
This type of phishing attack utilizes fake versions of both OU's SSO page and the default DUO request for SMS codes, making it one of the craftiest and most convincing attacks for OU personnel, particularly staff and faculty, as this method is able to bypass MFA.
The malicious actor will begin their attack by sending an email that prompts the recipient to log in to MySail. These types of emails can contain a large variety of topics; some of the most common subjects are Staff and Faculty Appreciation, Staff and Faculty Awards, Account ID Verification, Communicable Disease Reporting/Contact Tracing, and U.S. Immigration and Customs Enforcement (ICE). In the email below, you'll see that this email pertains to Immigration policy.

If the recipient has read the email and they're still unsure of its legitimacy, they can always hover over the hyperlink with their mouse and the URL will pop up in the bottom left-hand corner. The URL of the real OU SSO page WILL NEVER contain anything DUO related, regardless of whether you're staff/faculty or a student/member. Below is an example of a legitimate email from OU where the recipient has hovered over the link to confirm the URL without clicking on it.

If the recipient clicks on the link in the original phishing email, they'll be directed to a fake OU SSO page (similar attacks will direct the recipient to a Google Slide/Google Doc where they'll have to click another link to get to the fake OU SSO page). While this page is strikingly similar to the real OU SSO page in terms of color scheme, layout, and font details, it differs in the URL and functionality.

If the recipient is still unsure whether the email is part of a phishing campaign, they can enter random characters in the SSO page fields and then submit. If the SSO page forwards them to a DUO request and they're certain that the information they entered in the fields doesn't belong to anybody, they have confirmed that this is indeed a fake SSO page. A true DUO verification request will NEVER trigger with incorrect credentials.

At this point in the attack, if the recipient is a student or any OU personnel that doesn't require DUO verification, they will know immediately that this is a phishing campaign, as they should not be receiving DUO verification requests. For the OU personnel that do have DUO verification configured, it should be clear to tell that this is a fake DUO request based off of several factors: the URL is incorrect, there shouldn't be a loading symbol that repeats over-and-over again, there is no web icon (the image next to the text in the tab), it asks for a DUO Mobile Passcode but the tab says "DUO Push", etc.
This will pop up regardless of what the victim types in the fake OU SSO page; however, if the victim entered their actual credentials, then they will receive a true DUO authentication request from their device since the attacker uses their site to forward the victim's credentials to the actual OU SSO page, triggering the DUO verification request. If the victim clicks on the "Enter a code from the Duo Mobile app" link, it will redirect them here:

Lastly, if the victim has received a DUO verification request, entered the code in the field, and clicked "Verify", they will be redirected to an actual DUO page. Regardless if the code was correct, this will be shown:

5/19/2026: ICE & Communicable Diseases
In these attacks, the attacker uses recent topics prevalent in recent news to incite a feeling of panic and urgency in the user to respond.These messages are stated in the email to come from University Administration or other university authorities, but the emails used are normally compromised OU accounts, compromised accounts from other universities, or external email addresses. These messages normally state that the user should view a list that requires them to sign in to a fake SSO page to see. Once the user has signed in, their credentials are given to the attacker and are used to either further perpetuate the attack on OU, or the account is used as a proxy to target other universities.

12/05/2025: Fake Google Voicemail Phish Leading to Fake Google Sign-in Page
In this attack, the attacker pretends to leave fake Google voicemail with a link that leads to a fake Google voicemail page.

Clicking on the "Play Message" link in on this site takes the user to a fake Google sign in page where the user is lured into putting in their email and password and then told the password was wrong when nothing seems to happen.


08/04/2025: Credential Harvesting Phish via Fake SSO Page
In this phishing attack, the attacker uses a compromised account from another university to send a communicable illness phishing campaign targeting OU students.

The link in this email leads to a spoofed SSO page that attempts to replicate our legitimate one, but a key giveaway that this is a credential harvesting phish is that hovering over the URL in the email reveals a redirect to a Google Slides presentation.


03/04/2025: Updating/Authorizing 2SV
In this phishing scam, the perpetrator is disguising their attack to look like official campus communication. The email is attempting to get users to scan a malicious QR code and provide their phone number to try and gain access to more data through communication with the recipient.

11/7/2024: Fake Benefits Statement Form
In this phishing attack, the attacker, using a schoolcraft.edu address, attempts to get the recipient to fill out a form that they believe will give them a statement on their OU benefits. The recipient is taken to the Google Form on the right after clicking on the "View Your Statement" link in the email on the left. The Google Form importantly asks for a time based token from the DUO app.

4/30/2024: Credential Harvesting
In this phishing attempt, the attacker tries to solicit usernames and passwords by tricking the target into filling out a Google form.

04/11/2024: Yearbook
In this phishing attempt, the attacker tries to solicit personal information and money by claiming that they are distributing yearbooks for Oakland University. They charge a registration fee in addition to charging you for the "yearbook'



10/11/2023: STUDENT EMPLOYMENT OPPORTUNITY
In this phishing attempt, the attacker tries to recruit students for a job. In the email, the attacker created a Google Form to have you fill out personal information. Notice that it appears from a legitimate organization and that the recruiter is in another country and cannot meet you. It also mentions unspecified tasks and purchases you will have to make on their behalf.





7/20/2023: Undelivered message error
In this phishing attempt, the attacker poses as the university and is attempting to have you click on the link inside the email.

6/19/2023: Benefits Review
In this phishing attack, the attacker poses as a financial institution that tries to have the victim contact them under the guise of reviewing the benefits. You can verify this type of email's legitimacy by contacting OU's Benefits Department.

12/13/2022: Invoice for antivirus software renewal
In these phishing attempts, an attacker is attempting to make you believe you have been charged to renew an antivirus product subscription. The emails attempt to solicit contact by providing a number to call for support and/or to cancel the transaction. The sender email addresses are personal and not affiliated with the company or reputable reseller.


10/31/2022: Document shared with you:
In this phishing attempt, an attacker is attempting to make you believe a legitimate document has been shared with you. If you attempt to access the document it then requests you to disclose you NetID credentials and Duo MFA information in a Google form.



10/03/2022: !mportant
In this phishing attempt, an attacker is attempting to create a sense of urgency regarding a denied PayPal claim. There is a poorly crafted initial message which does not appear to be from a legitimate company. Attached is a semi-official looking PDF document back lacks personalization even though the name field is supposed to be populated.


09/30/2022: VP Requesting Assistance
In this phishing attempt, an attacker is attempting to impersonate an OU VP in an effort to start a dialogue with OU Staff member. If viewed in webmail you can see that Google marked the email as suspicious. Additionally you can see the email is coming from a non-OU account.

08/30/2022: Quickbooks
In this phishing attempt, an attacker is attempting to impersonate multiple companies, Quickbooks and Geek Squad in an effort to get the recipient to click on a link and/or download a file. In this instance the email was received at an OU email address despite the email appearing to be addressed to a Gmail address.

08/02/2022: Transfer Big Files
In this phishing attempt, an attacker is impersonating an OU user and attempting to get them click a link \ download a file.

5/31/2022: Silent Librarian: Attempt to steal NetID credentials via cloned SSO page
In this latest iteration of the Silent Librarian phishing attempt, an attacker used a compromised Oakland University email account to send an illegitimate notification to a group of users.

Unlike the previous post from 3/14/2022, the link in this email redirects to a cloned SSO page that is identical to our actual SSO page. The only noticeable difference between the two is the incorrect URL. This is a fairly sophisticated phishing attack.

If you filled out this form, please contact uts@oakland.edu immediately!
- Phishing Indicators:
- Sense of urgency
- Hovering over the link shows this directs to a non OU site
- Phone number in signature belongs to a different department
- Cloned OU SSO sign in page with incorrect URL
3/14/2022: Attempt to steal NetID credentials via imitation SSO page
An unsolicited email is received from an external sender, claiming to be the OU Technology Center, that requests the user to follow a link to re-activate an online certificate.

The link redirects to a poor imitation of OU's SSO page where the attacker is looking to steal NetID credentials that are entered.

If you filled out this form, please contact uts@oakland.edu immediately!
- Phishing Indicators:
- Email appears to be from an OU Account but is from an account outside OU
- Sense of urgency
- Hovering over the link shows this directs to a non OU site
- Imitation OU SSO sign in page
- Poor imitation
- Grammatical errors
- Request for personal information
3/7/2022: CoS impersonation attempt to steal credentials using imitation sign in page
This phishing attack is similar to the campaign we wrote about on 1/27/2022, except this message appears to come from OU's Chief of Staff.

The shared (March) Faculty Re-Scheduled Transcript.docx document contains a link to a web page that is an imitation of a Microsoft sign in page.

The attacker wants the user to enter their OU credentials into the web page so that they can steal them.

If you filled out this form, please contact uts@oakland.edu immediately!
- Phishing Indicators:
- Email appears to be from an OU Account but is from a personal Gmail account outside OU
- Hovering over the link shows this directs to a non OU site
- Imitation sign in page
- URL does not match official Microsoft URL
- Typo
- Request for personal information
2/14/2022: Tutoring scam attempts to steal bank funds
The phishing attack starts with an unsolicited email requesting a tutor for the sender's child or relative. In this instance, the sender referenced and contacted an actual OU professor in order to make the request seem as legitimate as possible.

After some correspondence between the sender and the recipient, the sender attempts to act on their objective.

- Phishing Indicators:
- Emotionally charged
- Obscure payment method
- Request for personal information
Should the recipient have went along with the sender's obscure request, a fraudulent check would be sent in which the funds don't exist. So when the money is returned to the relative, it would be removed from the recipient's bank account.
Reference: https://blogs.baylor.edu/phishing/2019/06/04/tutor-over-payment-scam/
01/27/2022: Attempt to steal a user's Email Address and Password using a form

The shared Faculty Evaluation_.docx has a link to a fillable form

The form tricks the user into giving away their Email Address and Password

If you filled out this form, please contact uts@oakland.edu immediately!
01/19/2022: Users targeted to update personal information in SAIL using a non OU Account

- Phishing Indicators:
- Email appears to be from an OU Account but is from a personal Gmail account
- Sense of Urgency
- Simultaneously to multiple recipients (vs a mailing list or individual notifications)
- Request for personal information
- Hovering over the link shows this directs to a non OU site
05/11/2021: Users were targeted with a cryptocurrency scam from a compromised OU account

- Phishing Indicators:
- Email appears to be from an OU Account but is signed by a 3rd party
- Sense of Urgency
- Request for personal information
03/22/2021: We received a phishing impersonating an OU account offering a tax refund


- Phishing Indicators:
- Although email appears to be from an OU Accountit is not
- Sense of Urgency
- Too Good to be True
11/30/2020: We received a phishing email impersonating the VP of Finance & Administration

- Phishing Indicators:
- Although email appears to be from an OU Vice President it is using a personal Google Account
- Sense of Urgency
- Request for non-standard contact message
- Grammar and capitalization errors
11/24/2020: We received a phishing email from a staff member claiming that their NetID would become deactivated unless they followed a suspicious link to reset their account.

- Phishing Indicators:
- Although email appears to be from UTS it is from another Higher-ED institution
- Sense of Urgency
- URL is obfuscated and does not point to OU (netid.oakland.edu)
Supplemental Phishing Examples:
Spear Phishing \ Impersonating an OU Employee

Spear Phishing \ Impersonating an OU Employee

- Phishing Indicators:
- Although email appears to be from an OU employee it is from a standard Google gmail account
- Sense of Urgency
- Unusual financial request
General Phishing

- Phishing Indicators:
- Although email appears to be from an OU Department it is from a non OU domain hr-adm.net
- Link points to a non-OU domain
General Phishing

- Phishing Indicators:
- Sense of Urgency
- Although email appears to be from an OU Department it is from a non OU account hr-adm.net
- Link and email address point to a non OU Domain
Additional Support
- OU Technology Center
- 44 Oakland Center
- Rochester, MI 48309-4479
- (248) 370-4357
- Office Hours: M-F 8:00am - 5:00pm