Phish: University of Toronto – termination of your UToronto Email

Published: July 25, 2024

This phishing email attempts to steal the user’s login credentials by providing false information about their UTORid being filed for deactivation. The email contains a link to a web page spoofed to look like a U of T web page. The URL mentioned in the email was also replicated to look like a UTORid-related web page.

Emails like this can cause panic for recipients, prompting them to act on the instructions without thinking. Always pause to think and look out for red flags when you receive a suspicious email.

Phish bowl

Email details

Subject:

University of Toronto – termination of your UToronto Email

Dear UToronto Email User,

According to our records, you recently requested the cancellation of your UToronto Email account.

If you were unaware of this request, it is recommended that you verify your account.

To verify your account click link below:

*malicious link*

If you do not verify your account, your account will be terminated.

Warm Regards,
*Fake email signature*

Phishing cues

  • Poses as a trusted or legitimate source

    The sender poses as U of T to influence the recipient into taking action.

  • Sense of urgency

    The email implies that the reader’s account will be deactivated if quick action isn’t taken. This sense of urgency encourages the reader to act under pressure without thinking.

  • Unprofessional design or formatting

    The email lacks typical professional formatting including a personalized greeting, legitimate signature and contact information.

  • Spelling and grammar mistakes

    The email contains grammatically incorrect sentences.

Image of spoofed webpage

Example of a spoofed webpage
Report phishing icon

Report phishing

If you have received a suspicious email like this one, please report it to report.phishing@utoronto.ca and delete it immediately from your mailbox. Don’t click any links, download attachments, engage with the sender or share the email with your contacts. If you engaged with the sender, please contact security.response@utoronto.ca immediately.