Original Phishing Message

From: jmaster[@]misd[.]net
Subject: Re: *** IT Report ***

Where Did the Link Lead?

The link foreversentiments[.]com/as led to a fake Outlook Web App login page. Always hover over links to see where they lead. Do not enter your credentials on websites you do not recognize or on online forms.

Tips for Detection

  • Notice the sender’s email is not @pugetsound.edu and the odd subject line.
  • An email platform (e.g. Outlook) is not typically where you would access pay slips. The inconsistency in what is changing should be a red flag.
  • Be aware of what tools the university provides. If phishing messages mention tools no longer provided or supported, that should be a red flag.
  • Notice the false sense of urgency (e.g. “MIGRATE immediately”)

Text of Phishing Message

From: jmaster[@]misd[.]net
Subject: Re: *** IT Report ***

To All,

Welcome to the new Web-Mail for Staff Single Sign-on. Migrate to the new Outlook Web app for Staff is the new home for online self-service and information.

Click on GATEWAY and login to:

• Access the new staff directory
• Access your pay slips and P60s
• Update your ID photo
• E-mail and Calendar Flexibility
• Connect mobile number to e-mail for Voicemail

Everyone is advise to MIGRATE immediately.

Please note that if this message is ignored you will experience difficulty in sending and receiving of email messages through our secure Web-mail Portal

Thanks
IT Service Desk
Copyright ©