Skip to content Accessibility statement

Phishing alert - fake voicemail notifications

News

Posted on Tuesday 29 September 2026

Be alert to a new phishing campaign targeting Google accounts, and find out what to do if you suspect you’ve been targeted.

We have recently seen a new type of phishing campaign attackers are using to gain access to Google accounts. The attack is in the form of a calendar invite containing a link to a voice mail message. These may appear to come from a University account or another institution or known contact who has already been exploited. Attackers will then use compromised accounts to target other colleagues.

What to do

  1. Stop and think. Take 6 seconds to think instead of acting on any pressure or urgency. 
  2. Never sign in via a voicemail notification that has not come from Zoom. To check genuine voicemails, open the Zoom app or visit the Zoom portal directly.
  3. Do not reply to unexpected calendar invites, (clicking Yes, No, or Maybe confirms your email is active).
  4. Report it by emailing itsupport@york.ac.uk and mark the message as spam in Gmail.
  5. Google Calendar adds every invitation you receive to your calendar automatically, even if you haven't accepted it. You can change this by going to Settings → Event settings → Add invitations to my calendar and turn off automatic additions.

What to remember

  1. University voicemail is provided through Zoom. 
  2. Any voicemail notification that doesn't come from Zoom, or that asks you to log in to listen through a link, should be treated as suspicious.
  3. A real Zoom voicemail message should come from: no-reply@zoom.us
  4. Even if you are sure a voicemail message is real, there’s no harm in logging in via Zoom to listen to it instead rather than clicking through the link. This is a good habit to get into.

What to do if you clicked the link and signed in:

Contact cert@york.ac.uk immediately. Fast action prevents the attacker from using your account to target others.