Skip to content Skip to main navigation Report an accessibility issue
Information Security

When Bad News Travels, Attackers Are Listening 


Service navigation


Malicious actors monitor news outlets and social media for signs of confirmed or suspected security events that they can exploit to their advantage. A campus outage that generates public discussion is, to them, an opportunity with a shelf life. The psychology is simple: during a disruption, people expect to hear from IT, so a call promising to fix the problem arrives as a relief rather than a warning sign. 

What is happening at UT 

Following the recent CAS authentication page issue, we have been made aware of a targeted vishing campaign, short for voice phishing, in which callers contact members of our community while posing as the Knoxville Campus, OIT HelpDesk. 

These calls are convincing by design. The call may reference the website issues by name and appear to know your department. None of that proves a call is legitimate; all of it is inexpensive to fake. The timing is no coincidence. When real support calls are arriving from every direction, one more does not stand out. 

What the vishing caller wants 

Their goal is to get you to share something valuable before the call ends: your NetID and password, a multi-factor authentication code, a push approval, or remote access to your computer. Expect pressure from a malicious caller, with messages like “Your account has been compromised,” “Your access is about to be suspended,” and “They need to verify your identity right now.” 

Five rules to keep you safe when receiving a suspicious call 

  1. Hang up. 
  1. Call back on a number you look up yourself, never the number provided by the caller. 
  1. Never share your password. The OneIT HelpDesk will never ask for it, by any channel, ever. 
  1. Never approve an MFA prompt you did not initiate, and never grant remote access to, or share your screen with, an unsolicited caller. 
  1. Report the suspicious call, whether or not you gave them any information or access. 

If you think you have been caught, please contact the OneIT HelpDesk immediately. We are here to help, and there is no penalty for reporting. Early reports make a real difference in how quickly we can contain an incident.