Original Phishing Message

From: Proma Bhattacharya <pbhatt24[@]umd[.]edu>
Subject: YOUR TOTAL COMPENSATION STATEMENT

Where did the link lead?

The link led to a form asking for your email and password. Scammers frequently use legitimate sites such as Google Forms or Microsoft Forms to collect sensitive data. Never enter your password on online forms or on login pages on sites you do not recognize.

Tips for Detection

  • Legitimate emails from the HR department will come from an @pugetsound.edu email address.
  • Paycheck and benefits information can be found in myPugetSound. If you are ever unsure of a link in an email, you can go directly to a trusted site to acquire the information.
  • Notice the odd capitalizations and the references to the university as “pugetsound”.
  • Always investigate links before clicking on them.

Text of Phishing Message

From: Proma Bhattacharya <pbhatt24[@]umd[.]edu>
Subject: YOUR TOTAL COMPENSATION STATEMENT

Thank you for being part of University of Puget Sound! We are glad that you are here, and we want you to know that your total compensation is made up of much more than what you see in your paycheck.

Total compensation statements bring visibility to the value of pugetsound employee benefits and time off policies. All pugetsound Staff/Non-Staff in regular positions have access to a Personalized online statement of total compensation. Individuals will be able to access their own statement upon logging in with their pugetsound credentials.

(Login required).

View your statement

Prepared by the Compensation Office

Department of Human Resources