{"id":1062,"date":"2023-04-04T12:32:50","date_gmt":"2023-04-04T19:32:50","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1062"},"modified":"2023-04-05T09:24:46","modified_gmt":"2023-04-05T16:24:46","slug":"phishing-from-04-01-2023-notification-of-account-suspension","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1062","title":{"rendered":"Phishing from 04\/01\/2023: &#8220;Notification of Account Suspension&#8221;"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><strong>From:<\/strong> Meta for Business &lt;appeal-form[@]metaforbusiness-support[.]com&gt;<br><strong>Subject: <\/strong>Notification of Account Suspension<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"535\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish-1024x535.png\" alt=\"\" class=\"wp-image-1064\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish-1024x535.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish-300x157.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish-768x402.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish-1440x753.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2023\/04\/4-1-23-meta-account-suspension-phish.png 1467w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>The sender\u2019s email address was from [@]metaforbusiness-support[.]com (which is not a valid FB\/Meta domain). Always double-check the sender\u2019s email address and don\u2019t solely rely on the display name.<\/li><li>The email had a generic greeting (e.g. Dear User or Dear Administrator).<\/li><li>The email tries to induce fear that your email service will be removed after 24 hours. Don\u2019t be misled by the sense of urgency!<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Text of Phishing Message <\/h2>\n\n\n\n<p><strong>From:<\/strong> Meta for Business &lt;appeal-form[@]metaforbusiness-support[.]com&gt;<br><strong>Subject: <\/strong>Notification of Account Suspension<\/p>\n\n\n\n<p>Dear Administrator of [<em>department name<\/em>] | Tacoma WA, <\/p>\n\n\n\n<p>We regret to inform you that your account on our platform has been suspended due to a violation of our terms of service. We take our policies seriously in order to ensure a positive and safe experience for all of our users. <\/p>\n\n\n\n<p>We understand that this may have been an unintentional mistake on your part, and we would like to provide you with an opportunity to appeal this decision. If you believe that your account has been suspended in error, please submit an appeal by clicking on the &#8220;Submit&#8221; button below. <\/p>\n\n\n\n<p>Submit [<em>link removed<\/em>]<\/p>\n\n\n\n<p>Please note that the review process can take up to [insert time frame] to complete. We appreciate your patience and cooperation in this matter. <\/p>\n\n\n\n<p>If your appeal is successful, your account will be reinstated and you will be able to resume using our platform. If your appeal is not successful, your account will remain suspended. <\/p>\n\n\n\n<p>Thank you for your understanding and for your commitment to our policies. <\/p>\n\n\n\n<p>Best regards, Facebook Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: Meta for Business &lt;appeal-form[@]metaforbusiness-support[.]com&gt;Subject: Notification of Account Suspension Tips for Detection The sender\u2019s email address was from [@]metaforbusiness-support[.]com (which is not a valid FB\/Meta domain). Always double-check the sender\u2019s email address and don\u2019t solely rely on the display name. The email had a generic greeting (e.g. Dear User or Dear Administrator). [&hellip;]<\/p>\n","protected":false},"author":643,"featured_media":1064,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-1062","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/643"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1062"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1062\/revisions"}],"predecessor-version":[{"id":1066,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1062\/revisions\/1066"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1064"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}