October Phishing Workshop Recap

Last week, on October 10th, the PrISM team conducted their monthly phishing workshop. For those who may have missed it,

Stylized depiction of phishing email
October 15, 2025

Phishing via Teams 
Phishing is generally conducted from emails; however, UBC has faced its first case of Phishing via Teams. Claiming to be part of UBC’s IT support team, a cybercriminal attempted to convince a staff member to share their screen and allow remote control. These “Living off the Land” (LOTL) attacks are a type of cyberattack that relies on already installed software (Teams) to carry out malicious activity, making it harder to detect. 

Fortunately, the staff member realized something was off and reported the situation. The Cybersecurity team was then able to contain the threat.  

Fake Invoice 
Sixteen staff members reported receiving fake invoices from cybercriminals impersonating UBC members. At a glance, these fake invoice pdfs were indistinguishable from real invoices.  

What can I do to protect myself? 

  • Be cautious of unsolicited requests: Legitimate UBC IT staff will never ask you to grant remote control of your screen through Teams or any other platform without prior communication. 
  • Check who you’re talking to: If someone claims to be IT support, double-check their email address or Teams profile before responding. 
    If you’re unsure, contact IT directly through official channels. 
  • Report suspicious activity right away: If something feels off, trust your instincts. Report it immediately to UBC Cybersecurity at security@ubc.ca. Quick reporting is often the difference between stopping an attack and a successful compromise. 

Page last updated on October 15, 2025


UBC Crest The official logo of the University of British Columbia. Urgent Message An exclamation mark in a speech bubble. Bluesky The logo for the Bluesky social media service. Bookmark A bookmark in a book. Browser A web browser window. Caret An arrowhead indicating direction. Arrow An arrow indicating direction. Arrow in Circle An arrow indicating direction. Arrow in Circle An arrow indicating direction. Time A clock. Chats Two speech clouds. E-commerce Cart A shopping cart. Facebook The logo for the Facebook social media service. Help A question mark in a circle. Home A house in silhouette. Information The letter 'i' in a circle. Instagram The logo for the Instagram social media service. Linkedin The logo for the LinkedIn social media service. Location Pin A map location pin. Mail An envelope. Menu Three horizontal lines indicating a menu. Minus A minus sign. Pencil A pencil indicating that this is editable. Telephone An antique telephone. Play A media play button. Plus A plus symbol indicating more or the ability to add. Search A magnifying glass. Settings A single gear. Arrow indicating share action A directional arrow. Speech Bubble A speech bubble. Star An outline of a star. Twitter / X The logo for the X (aka, Twitter) social media service. User A silhouette of a person. Vimeo The logo for the Vimeo video sharing service. Youtube The logo for the YouTube video sharing service.