Original Phishing Message

From: llindsay[@]misd[.]net
Subject: Re: IT Microsoft Outlook Update
Subject: Re: Mailbox Migration

Tips for Detection

  • The university uses Google Mail which does not require using Outlook. This should raise suspicion.
  • Notice the sender’s email is from the misd[.]net domain. Emails from Technology Services will generally come from a pugetsound.edu email.
  • Hovering over the link reveals that it goes to bestrollingstoneconcert[.]com/sr/ which is not a pugetsound.edu site.
  • Notice the false sense of urgency in the email with wording such as “take effect now” and “lose your account”.

Where Did the Link Lead?

The link led to a fake Outlook Web App login page. Never enter your credentials on sites you do not recognize.

Text of Phishing Message

From: llindsay[@]misd[.]net
Subject: Re: IT Microsoft Outlook Update
Subject: Re: Mailbox Migration

To All,

We are migrating all email accounts into the latest Microsoft Outlook 2024 and as such all active Account holders are to verify and Log in for the upgrade and migration to take effect now. This is done to improve the security and efficiency.

Click Microsoft Outlook Portal for migration.

Note: You might lose your account if you fail to Migrate to the latest Outlook web App webmail.

Best Regards,
Lindsay Lynda
ITS Help-desk