Original Phishing Message

Note: If you received this message, please simply delete the message. Do not click any links and do not enter or reply with any information.

Tips for Detection

  • Notice the “Caution” banner that was applied to the top of the message. Technology Services adds the banner on emails that match patterns of previous phishing attempts.
  • The sending email address is from the cornwallhospital[.]ca domain. This is not a Puget Sound address.
  • Technology Services will not ask you to click a link to protect your email or to upgrade your email.
  • The display name “Barretto, Dawn” versus the name in the email signature “Josselin Issabelle” do not match. Further, neither individuals work at the university.

Where did the link lead?

The link led to a fraudulent Outlook sign in page. Note: If you entered your credentials on this page, please immediately change your password and contact the Service Desk at x8585. Your credentials are likely compromised.

Text of Phishing Message

From: Dawn.Barretto[@]cornwallhospital[.]ca
Subject: IT Services Department

All our Outlook Users are at risk today.

You were contacted by the IT Services Department In an approach to Protect our Email Data, which you ignored. We received a severe unsolicited message sent in bulk to all our outlook Users. Please secured your email NOW with our new anti-Spam Mailinblack, for your mail to be delivered, please Protect your email now by visiting our anti-Spam Mailinblack Portal at https://app[.]getresponse[.]com/site2/dawnbarretto/?u=QvzCa&webforms_id=zZIsP and install the anti-Spam Mailinblack Software.

Regards,
Josselin issabelle
IT Service Desk Support
IT-Support Analyst
Information Technology Services DEPT.