Thursday, July 23, 2026

Important Security Update: Protect Yourself Against Active Phishing and Vishing Scams

Submitted by Ashton Massey

The IT department has been notified of two active campaigns currently targeting government entities and small businesses: a phishing (email) campaign and a vishing (voice phishing) campaign. Threat actors are using these methods to steal user credentials, personal information (such as banking details and SSNs), and company data (including HR records, financials, and patron information).

Even if you do not use DocuSign, you are at risk of receiving these targeted attacks. Please review the following information to keep yourself and the library secure.

Current Threats to Watch For:

  • Email Phishing: Scammers are sending spoofed emails designed to look like official DocuSign communications. Alternatively, they may send a real DocuSign file that contains a harmful link inside the document. Note that these scams are currently prominent with DocuSign, but are not strictly limited to it.
  • Phone Vishing: Scammers are calling staff and impersonating IT department members. They will often ask for your login information, instruct you to reset your password to one they specify, or try to get you to download remote software and click suspicious links.

What to Look For:

  • Urgent Language and Threats: Both malicious emails and phone calls frequently rely on urgent language, unusual requests, or threats of consequences to rush you into making a mistake.
  • Requests for Passwords: The IT department will NEVER ask for your password.
  • Suspicious Links: Do not click! Instead, hover your mouse over a link in an email. The real destination will appear in the bottom-left corner of your screen; if the link doesn't match where it claims to go, it is likely spam.
  • Sender Details and Context: Check the sender's email address and ask yourself if the email is genuinely meant for you or if it looks generic.
  • Robotic or Odd Speech: Pay attention to how a caller sounds, as impersonators have been known to use AI to replicate the voices of known contacts.

What to Do:

  • Do Not Engage: If you receive a suspicious call, hang up the phone immediately. For emails, do not click on any links in the attachment or download any files.
  • Do Not Share Information: Never share your password with anyone, including members of IT or other staff members. Avoid giving out ANY information unless you are absolutely certain the person is who they claim to be, as you never know what information they are trying to gather.
  • Verify Contacts: If you receive a questionable email from an FCPL staff member or vendor, verify its authenticity by calling them directly rather than emailing them back.
  • Report Emails: Forward any phishing emails to "phishing@forsythpl.org" or submit a help desk ticket.
  • Report Calls: Report suspicious phone incidents immediately to the IT Emergency Hotline at 678-780-1821.
  • Ask for Help: If you are ever unsure about an email, contact the IT department before clicking on any links.
Thank you for helping us keep FCPL, our staff, and our patrons safe and secure. As always, if you have any questions or concerns, please submit a help desk ticket.

No comments:

Post a Comment