UBC IT memo: Phishing attacks targeting UBC Payroll and HR Accounts

UBC Cybersecurity is urgently raising awareness of a university payroll scam targeting UBC, the same threat recently active at a number of U.S. universities. Over the past two weeks, several UBC accounts were compromised. 

These emails impersonate HR, Finance, or senior administrators, referencing pay, bonuses, or leave approvals. Attackers are typically successful in sending an MFA “push” to the user who approved it.

  1. “Employee Salary Adjustment Approval1” 
  2. “Q2 Payroll and Compensation Update – Action Needed University of British Columbia” 
  1. Verify any HR or pay-related message before clicking links. 
  2. Never approve MFA prompts you didn’t initiate. 
  3. Use strong, unique passwords or passphrases and never reuse your UBC credentials elsewhere. 
  4. Remind staff to verify any pay- or HR-related communications through trusted channels (Teams, phone, or official Workday links).
  5. Report suspicious messages to security@ubc.ca

To learn more, visit: https://privacymatters.ubc.ca/news/payroll-pirates-phishing-attacks 

Thank you for helping keep our UBC systems and data safe. 

Sincerely,

Administrative Team & Psychiatry IT UBC Department of Psychiatry