Summary
We are seeing emails impersonating the “GARNET IT Service Desk” claiming that your mailbox is over quota or will be deactivated within 24 hours. The messages link to a look-alike login page designed to steal garnet.edu.gh credentials. Several variations are in circulation; the sending addresses and link domains change frequently.
How to recognise it
- Urgent language and threats of account closure or quota limits.
- A link whose domain is not
garnet.edu.gh(hover before clicking). - A login page that asks for your full password after you already appear to be “signed in”, or that requests a one-time MFA code.
- Generic greetings (“Dear User”) and subtle spelling/branding errors.
Recommended actions
- Do not click the link or enter your credentials. Legitimate GARNET services will never ask you to confirm your password by email.
- Report the message. Forward suspicious emails to
csirt@garnet.edu.gh, then delete them. - If you already entered your password, change it immediately from a trusted device, sign out of all sessions, and report an incident so we can help secure the account.
- Enable multi-factor authentication (MFA) if you have not already — it blocks most credential-theft attempts even when a password is exposed.
Update — 2026-08-03
A second wave using SMS (“smishing”) links has been observed alongside the email campaign. The same guidance applies: verify the domain and never enter credentials from a link you did not initiate.
This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:
Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.
Think a system in the community is affected or compromised?Report an incident