Recent phishing waves show a shift away from generic, easily spotted spam. Today, attackers rely heavily on deceptive Google Workspace notifications, fake document shares, spoofed internal emails, and credential-stealing login pages designed to mimic official login portals.
What hasn’t changed are still the three most common social engineering tactics.
1. The Document Share Scam
- The Trap: An email arrives indicating a principal, board member, or patron shared a file via Google Docs or Office 365. Clicking the link redirects to a counterfeit authentication page or a malicious third-party OAuth app request. Entering credentials hands the attacker total account access—and access to every attached student/patron record.
- The Defense: Never sign in or enter credentials on a page reached through an unexpected email link. Inspect the browser address bar to ensure it is hosted on an official domain (*.google.com), and access files directly by opening Google Drive rather than clicking the link.
2. The Urgent Gift Card Request – old but still works
- The Trap: Staff receive a brief email appearing to come from a principal, library director, or superintendent: “I’m in a meeting and need gift cards for a staff appreciation event right away. Can you purchase them and email me the codes?”
- The Defense: Treat urgent, out-of-band financial requests as immediate red flags. Organizations do not authorize official purchasing or gift card procurement via unverified email requests. Always confirm through a direct phone call or in-person before taking action.
3. Fake Vendor Invoices and Purchase Orders
- The Trap: Attackers target administrative assistants, librarians, and finance staff with fraudulent invoices or updated direct deposit forms from familiar book distributors, SaaS providers, or maintenance vendors. These messages often include direct PDF links designed to drop malware or harvest credentials.
- The Defense: Verify any change to vendor payment details or unexpected invoices using a pre-established phone number on file—never the contact phone number or email address listed inside the suspicious document itself.
Red Flag List
- Urgency: The message demands immediate action to avoid penalty, account suspension, or missed deadlines..
- Mismatched Sender Addresses: The display name says “Superintendent Smith,” but hovering over the sender reveals principal-office-update@gmail.com or a lookalike domain.
- Unexpected Credentials Prompts: A link forces a password sign-in when already authenticated to the network.
When in doubt, report the email using your organization’s phishing report button or forward it to the IT help desk before clicking any links.
