Phishing alert - fake voicemail notifications
News
Posted on Tuesday 29 September 2026
Be alert to a new phishing campaign targeting Google accounts, and find out what to do if you suspect you’ve been targeted.
We have recently seen a new type of phishing campaign attackers are using to gain access to Google accounts. The attack is in the form of a calendar invite containing a link to a voice mail message. These may appear to come from a University account or another institution or known contact who has already been exploited. Attackers will then use compromised accounts to target other colleagues.
What to do
- Stop and think. Take 6 seconds to think instead of acting on any pressure or urgency.
- Never sign in via a voicemail notification that has not come from Zoom. To check genuine voicemails, open the Zoom app or visit the Zoom portal directly.
- Do not reply to unexpected calendar invites, (clicking Yes, No, or Maybe confirms your email is active).
- Report it by emailing itsupport@york.ac.uk and mark the message as spam in Gmail.
- Google Calendar adds every invitation you receive to your calendar automatically, even if you haven't accepted it. You can change this by going to Settings → Event settings → Add invitations to my calendar and turn off automatic additions.
What to remember
- University voicemail is provided through Zoom.
- Any voicemail notification that doesn't come from Zoom, or that asks you to log in to listen through a link, should be treated as suspicious.
- A real Zoom voicemail message should come from: no-reply@zoom.us
- Even if you are sure a voicemail message is real, there’s no harm in logging in via Zoom to listen to it instead rather than clicking through the link. This is a good habit to get into.
What to do if you clicked the link and signed in:
Contact cert@york.ac.uk immediately. Fast action prevents the attacker from using your account to target others.