Text Message Scam Circulating on Campus
Dear Columbia colleagues,
The CUIT Security Office is issuing an advisory regarding an ongoing surge in executive and departmental leadership impersonation via text message (smishing).
What the Scam Looks Like
Scammers use publicly available information to identify senior university leaders (such as Deans, Department Chairs, or Executives) and their team members. They send an SMS claiming to be that leader, often stating they are “stuck in a meeting” or “handling an urgent matter,” and request immediate assistance. Typically, they ask the recipient to purchase retail gift cards, wire funds, or share personal contact information.
Key Rules to Remember
- University leadership will never request gift card purchases, personal banking transactions, or wire transfers via text message.
- Verify out-of-band: If you receive an urgent or unusual request from a colleague or supervisor via SMS, independently verify their identity by calling their known campus extension or messaging them on official university platforms. Do not reply to the text.
- Check the sender: Scammers routinely use spoofed names with unrecognized out-of-state or virtual phone numbers.
What to Do If You Receive a Suspicious Text
- Do not respond, click any links, or provide information.
- Forward the message to 7726 (SPAM) on your mobile device to alert AT&T and Verizon
- For further information on reporting unwanted calls & texts
• Take a screenshot of the message (including the sender's phone number) and report it to the CUIT Security Office at security@columbia.edu
Jose Santiago
AVP of Client Support Services
Columbia University Information Technology
Medha Bhalodkar
CISO and AVP, Enterprise Risk Management
Columbia University Information Technology