---
title: 'Active phishing campaign targeting garnet.edu.gh webmail accounts'
summary: >-
  GARNET CSIRT is tracking a credential-harvesting campaign that impersonates
  the IT service desk and directs users to a fake webmail login page. Do not
  enter your credentials; report suspicious messages.
severity: high
status: active
advisoryId: GARNET-CSIRT-2026-002
published: 2026-08-01
updated: 2026-08-03
affected:
  - 'garnet.edu.gh email / webmail users'
tags:
  - phishing
  - credential-theft
  - email
tlp: CLEAR
references:
  - title: 'Recognise and report phishing (CISA)'
    url: 'https://www.cisa.gov/secure-our-world/recognize-and-report-phishing'
---

## Summary

We are seeing emails impersonating the "GARNET IT Service Desk" claiming that
your mailbox is **over quota** or will be **deactivated within 24 hours**. The
messages link to a look-alike login page designed to steal garnet.edu.gh
credentials. Several variations are in circulation; the sending addresses and
link domains change frequently.

## How to recognise it

- Urgent language and threats of account closure or quota limits.
- A link whose domain is **not** `garnet.edu.gh` (hover before clicking).
- A login page that asks for your full password after you already appear to be
  "signed in", or that requests a one-time MFA code.
- Generic greetings ("Dear User") and subtle spelling/branding errors.

## Recommended actions

1. **Do not click the link or enter your credentials.** Legitimate GARNET
   services will never ask you to confirm your password by email.
2. **Report the message.** Forward suspicious emails to
   `csirt@garnet.edu.gh`, then delete them.
3. **If you already entered your password,** change it immediately from a
   trusted device, sign out of all sessions, and
   [report an incident](/report/) so we can help secure the account.
4. **Enable multi-factor authentication (MFA)** if you have not already — it
   blocks most credential-theft attempts even when a password is exposed.

## Update — 2026-08-03

A second wave using SMS ("smishing") links has been observed alongside the email
campaign. The same guidance applies: verify the domain and never enter
credentials from a link you did not initiate.
