


Watch Out for Document Requests!
Lately, we’ve seen a sharp rise in a very specific type of phishing. We’re talking about emails that look exactly like SharePoint or Microsoft 365 notifications. They can look pretty convincing because they often come from real accounts—though usually, those accounts have been hacked.
TL;DR – Feeling Doubtful? Check This First!
Did you get a notification about a shared document on SharePoint or OneDrive (like a payroll or HR file)? Ask yourself these questions before doing anything:
If you’re unsure:
Don't click any links, don't enter your password anywhere, and report the message to cert@utwente.nl
What does a phishing email like this look like?
Take a look at this example:

At first glance, it seems okay—the subject line mentions a University of Twente document. But the devil is in the details. In these types of emails, you'll often see:
This is a massive red flag. If a message is about UT documents but comes from a different school or an unknown organization, stay far away.
How to recognize these phishing attempts?
1. Unexpected document requests
Out of the blue notifications that someone shared a file? Think for a second:
Note: A "payroll notice," invoice, or HR document without any context is almost always suspicious.
2. The sender and content don't match
Check if the sender makes sense.
Remember: Even if the account is legit, it might be compromised.
3. Urgency or "Clickbait"
Attackers love to play on your emotions. They use urgent or curious subjects like "Payroll Notice," "Invoice," "Secure Document," or "Password Expiry" to get you to click without thinking.
4. A login page after clicking the link
If you click a link and immediately land on a login page, pay attention:
Phishing sites often look like the real Microsoft login page:

In the example above, the document is hosted on another university's environment, even though it claims to be a UT payroll file. That’s a clear sign it’s fake.
5. Does this fit the normal way of working?
Ask yourself: Is this how we usually do things?
What happens if you accidentally log in??
If you enter your details on a phishing page, the attackers get full access to your account. They’ll then use your account to send new phishing emails to your colleagues and fellow students. This is how the attack spreads like wildfire through the organization. We’ve even seen hacked accounts being used to send "free product" scams recently.
What should you do?
By staying sharp, you're not just protecting your own account, you're keeping the whole UT community safe!