Recently, attackers have continued to use AI device-code phishing techniques. They may send fake messages disguised as shared files, voice messages, account-expiration notifications, course-related notices, or official document notifications to trick users into signing in.
Please pay special attention:
A Real URL ≠ A Real Request
Even if you are directed to a legitimate official verification page, it does not mean that the login request is safe.
If you are not personally setting up the device, cancel any device-code sign-in request first!
Attackers may use shared files, voice messages, account-expiration notifications, course-related notices, or official document notifications to guide you through the sign-in process.
You may be directed to a legitimate official verification website. However, please remember: a real URL does not mean that the sign-in request is real.
When you enter the device code provided by the attacker and complete multifactor authentication (MFA), you may actually be authorizing an unfamiliar device.
After obtaining a login session, the attacker may gain unauthorized access to or expose Outlook, OneDrive, and university data.
Do not enter a device code at the direction of an unfamiliar message or another person, and do not complete MFA verification for an unknown device.
Open Outlook, OneDrive, or other systems by accessing them directly through the portal. Avoid following instructions in suspicious messages.
If you did not set up a new device but received a device-code sign-in request, cancel it immediately and do not continue.
Keep the suspicious message or take a screenshot, stop operating and report it immediately.
Do not enter device codes provided by others.
Open systems only from the portal.
Screenshot suspicious messages and report them immediately.
To learn more about cybersecurity information, please scan the QR Code.