HighTLP:CLEARGARNET-CSIRT-2026-002

Active phishing campaign targeting garnet.edu.gh webmail accounts

GARNET CSIRT is tracking a credential-harvesting campaign that impersonates the IT service desk and directs users to a fake webmail login page. Do not enter your credentials; report suspicious messages.

High severity. Remediate as a priority.

Summary

We are seeing emails impersonating the “GARNET IT Service Desk” claiming that your mailbox is over quota or will be deactivated within 24 hours. The messages link to a look-alike login page designed to steal garnet.edu.gh credentials. Several variations are in circulation; the sending addresses and link domains change frequently.

How to recognise it

  • Urgent language and threats of account closure or quota limits.
  • A link whose domain is not garnet.edu.gh (hover before clicking).
  • A login page that asks for your full password after you already appear to be “signed in”, or that requests a one-time MFA code.
  • Generic greetings (“Dear User”) and subtle spelling/branding errors.
  1. Do not click the link or enter your credentials. Legitimate GARNET services will never ask you to confirm your password by email.
  2. Report the message. Forward suspicious emails to csirt@garnet.edu.gh, then delete them.
  3. If you already entered your password, change it immediately from a trusted device, sign out of all sessions, and report an incident so we can help secure the account.
  4. Enable multi-factor authentication (MFA) if you have not already — it blocks most credential-theft attempts even when a password is exposed.

Update — 2026-08-03

A second wave using SMS (“smishing”) links has been observed alongside the email campaign. The same guidance applies: verify the domain and never enter credentials from a link you did not initiate.

§ Verify this advisory✓ PGP-signed

This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:

$ curl -O https://csirt.garnet.edu.gh/advisories/2026-002-webmail-phishing-campaign.md
$ curl -O https://csirt.garnet.edu.gh/advisories/2026-002-webmail-phishing-campaign.md.asc
$ gpg --import garnet-csirt.asc
$ gpg --verify 2026-002-webmail-phishing-campaign.md.asc 2026-002-webmail-phishing-campaign.md

Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.


Think a system in the community is affected or compromised?Report an incident