{"id":1257,"date":"2024-08-26T08:25:09","date_gmt":"2024-08-26T15:25:09","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1257"},"modified":"2024-08-26T08:35:09","modified_gmt":"2024-08-26T15:35:09","slug":"phishing-from-8-26-24-syncing-error-password-expiry","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1257","title":{"rendered":"Phishing from 8\/26\/24: &#8220;Syncing Error Password Expiry&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Message<\/p>\n\n\n\n<p><strong>From<\/strong>: ADMIN-CPANEL@vnwzsi.org<br><strong>Subject:<\/strong> Syncing Error Password Expiry<br><strong>Subject<\/strong>: Password Expiry Notification [<em>username<\/em>]@pugetsound.edu<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"674\" height=\"480\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry.jpg\" alt=\"\" class=\"wp-image-1258\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry.jpg 674w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-300x214.jpg 300w\" sizes=\"auto, (max-width: 674px) 100vw, 674px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The email was sent from ADMIN-CPANEL[@]vnwzsi[.]org. This is not an @pugetsound.edu email address.<\/li><li>TS will never ask you to click a link to keep the same password. <\/li><li>Notice the false sense of urgency and grammatical errors (e.g. &#8220;will be expires today&#8221;)<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where did the link lead?<\/p>\n\n\n\n<p>The link led to a fake Webmail login page. Never enter your credentials on sites you do not recognize. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"522\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link-1024x522.jpg\" alt=\"\" class=\"wp-image-1261\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link-1024x522.jpg 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link-300x153.jpg 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link-768x391.jpg 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link-1440x734.jpg 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2024\/08\/8-26-24-password-expiry-link.jpg 1497w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: ADMIN-CPANEL@vnwzsi.org <br><strong>Subject:<\/strong> Syncing Error Password Expiry<br><strong>Subject<\/strong>: Password Expiry Notification [<em>username<\/em>]@pugetsound.edu <\/p>\n\n\n\n<p>webmail<br>pugetsound.edu,<br>Your account [<em>username<\/em>]@pugetsound.edu password will be expires today 8\/26\/2024 11:42:14 p.m.<\/p>\n\n\n\n<p>Please kindly use the button below to continue with the same password.<\/p>\n\n\n\n<p>Keep Same Password<\/p>\n\n\n\n<p>Automated Message 8\/26\/2024 11:42:14 p.m.<br>pugetsound.edu<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Message From: ADMIN-CPANEL@vnwzsi.orgSubject: Syncing Error Password ExpirySubject: Password Expiry Notification [username]@pugetsound.edu Tips for Detection The email was sent from ADMIN-CPANEL[@]vnwzsi[.]org. This is not an @pugetsound.edu email address. TS will never ask you to click a link to keep the same password. Notice the false sense of urgency and grammatical errors (e.g. &#8220;will be expires [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1258,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-1257","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1257"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1257\/revisions"}],"predecessor-version":[{"id":1262,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1257\/revisions\/1262"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1258"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}