Smishing

What is Smishing?

Smishing (SMS phishing) is a type of phishing attack that uses text messages or other mobile messaging services to trick you into revealing sensitive information, clicking a malicious link, downloading harmful software, sending money, or contacting a fraudulent phone number.

Colleges and universities are attractive targets for smishing because campus communities include large numbers of students, faculty, staff, alumni, applicants, and third-party partners who regularly receive time-sensitive communications. Attackers may take advantage of familiar university processes, services, and terminology to make fraudulent text messages appear legitimate.

A smishing message may appear to come from CSUN, a professor or supervisor, an IT support team, a financial institution, a delivery service, a government agency, or another organization you trust.

Recent Smishing at CSUN

CSUN has recently seen smishing texts that impersonate President Beck and ask whether you are available. These messages are designed to start a conversation and build trust. The scammer will eventually ask you to send money, purchase gift cards, or make another type of payment.

If you receive one of these messages, do not respond or send money. Forward the suspicious text to abuse@csun.edu for review.

Remember that university leaders, faculty members, supervisors, and other colleagues can be impersonated. If you receive an unusual request that appears to come from someone at CSUN, verify the request independently using contact information you already know or information published on an official CSUN website.

Common Smishing Scams

Be especially cautious of unexpected text messages involving:

  • Impersonation of university leadership, faculty, or supervisors: An attacker may pretend to be the university president, a dean, department chair, professor, supervisor, or coworker. The initial message may simply ask whether you are available before progressing to a request for money, gift cards, or other assistance.
  • Financial aid, FAFSA, or student loans: Messages may promise additional financial aid, loan forgiveness, or urgent assistance with a student loan. Never provide your FSA ID, password, or other account credentials in response to an unsolicited message.
  • Scholarships and grants: Scammers may claim that you have been selected for a scholarship or grant but must provide personal information or pay a fee before receiving the funds.
  • Tuition and student account balances: A message may claim that tuition or another university charge is overdue and threaten to drop your classes, place a hold on your account, or impose a penalty unless you pay immediately.
  • University account problems: Attackers may claim that your CSUN account, email, Microsoft 365 account, learning management system, or another campus service will be suspended unless you sign in or verify your identity.
  • Multi-factor authentication (MFA): A message may ask you to provide an authentication code, approve an unexpected login, or visit a fraudulent sign-in page. Never share an MFA code with another person or approve a login you did not initiate.
  • Employment opportunities: Students may receive unexpected offers for campus jobs, internships, research positions, personal assistant positions, or remote work. Be suspicious when someone sends you a check, asks you to purchase gift cards, requests banking information, or asks you to send money elsewhere.
  • Registration and enrollment: Messages may claim that you need to verify your enrollment, resolve a registration problem, or take immediate action to prevent your classes from being dropped.
  • Refunds and payments: A message may claim that you are entitled to a tuition refund, financial aid disbursement, reimbursement, or other payment and ask for banking or account information.
  • Campus alerts and services: Attackers may imitate parking notices, library notifications, campus events, technology support, housing information, surveys, or other familiar university services.

How to Recognize Smishing

Be suspicious of an unexpected text message that:

  • Creates urgency or pressures you to act immediately.
  • Asks you to click a link, scan a QR code, call an unfamiliar number, or download an application.
  • Requests a password, verification code, financial information, Social Security number, or other sensitive information.
  • Claims there is a problem with an account, payment, package, toll, refund, or purchase.
  • Offers an unexpected prize, refund, job, or financial opportunity.
  • Comes from an unfamiliar number or sender.
  • Contains a web address that does not match the organization it claims to represent.

Remember that a message can look professional and still be fraudulent. Advances in automation and artificial intelligence can help attackers create convincing, personalized messages with correct spelling and grammar.

Verify Through CSUN, Not Through the Message

If a text claims to concern your CSUN account, classes, financial aid, tuition, employment, or another university service, do not use the link, phone number, or contact information contained in the message to verify it.

Instead:

  1. Go directly to the official CSUN website or service you normally use.
  2. Contact the appropriate CSUN department using contact information published on an official csun.edu webpage.
  3. If the message concerns financial aid or your student account, verify the information directly through the appropriate CSUN student services.
  4. If the message concerns your CSUN account or technology services, contact CSUN IT using official CSUN contact information.
  5. Forward suspicious CSUN-related text messages to abuse@csun.edu.

Protect Your University Accounts

  • Never provide your password or MFA verification code in response to a text message.
  • Never approve an MFA request you did not initiate.
  • Do not sign in to a university account through an unexpected text-message link.
  • Use strong, unique passwords and approved multi-factor authentication.
  • Verify unusual requests from university leaders, faculty, supervisors, coworkers, or university departments through a separate, trusted communication method.
  • Remember that sender names, phone numbers, university logos, job titles, and familiar terminology can be spoofed.

When in doubt, don't use the information in the text to verify the text. Go directly to the trusted source.

Example of a Recent Smishing Text:

If you receive an unsolicited text from an unrecognizable number, IGNORE or DELETE it. We have received reports of fraudulent text messages purporting to come from President Beck. This is a fraudulent attempt to solicit money. Please DO NOT REPLY OR RESPOND TO THE TEXT MESSAGE. Other CSU campuses are receiving similar attempts pretending to come from their institutional leadership.

Smishing text message

Additional Resources