{"id":1390,"date":"2025-12-05T13:00:13","date_gmt":"2025-12-05T21:00:13","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=1390"},"modified":"2025-12-05T13:11:52","modified_gmt":"2025-12-05T21:11:52","slug":"phishing-from-12-5-2025-university-of-puget-sound-total-compensation-statement","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/1390","title":{"rendered":"Phishing from 12\/5\/2025: &#8220;University Of Puget Sound Total Compensation statement&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> ayomideismaheel042[@]gmail[.]com<br><strong>Subject<\/strong>: University Of Puget Sound Total Compensation statement<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"445\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-1024x445.png\" alt=\"\" class=\"wp-image-1391\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-1024x445.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-300x130.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-768x334.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish.png 1056w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Notice the email is from an @gmail[.]com address. Legitimate emails from Human Resources will generally come from an @pugetsound.edu address.<\/li>\n\n\n\n<li>An email only containing a link is suspicious. Even though the link goes to Google Drive, beware that scammers use legitimate file-sharing tools. <\/li>\n\n\n\n<li>Notice that the attachment is a .docm. That file is in a Word Document format with Macros. Macros can execute malicious scripts on your computer. <\/li>\n\n\n\n<li>Notice the link to view the statement goes to a suspicious site (ms-secure-signin-online-nlc-lldas[.]vercel[.]app). Always use caution with links and never enter credentials on web forms or on sites you do not recognize. <\/li>\n<\/ul>\n\n\n\n<p class=\"has-large-font-size\">Image of Message Attachment<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"423\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-1024x423.png\" alt=\"\" class=\"wp-image-1392\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-1024x423.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-300x124.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-768x317.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-1536x634.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment-1440x594.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2025\/12\/12-5-25-compensation-statement-phish-attachment.png 1916w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Message Attachment<\/p>\n\n\n\n<p>Thank you for being part of University of Puget sound We are glad that you are here, and we<br>want you to know that your total compensation is made up of much more than what you see in your paycheck.<\/p>\n\n\n\n<p>Total compensation statements bring visibility to the value of University of Puget. benefits and time off policies. All University of Puget Staff\/Non-Staff in regular positions have access to a<br>Personalized online statement of total compensation. Individuals will be able to access their own statement upon logging in with them University of Puget credentials.<\/p>\n\n\n\n<p>View your statement<\/p>\n\n\n\n<p>Prepared by the Compensation Office<br>Department of Human Resources<br>University of Puget<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message From: ayomideismaheel042[@]gmail[.]comSubject: University Of Puget Sound Total Compensation statement Tips for Detection Image of Message Attachment Text of Message Attachment Thank you for being part of University of Puget sound We are glad that you are here, and wewant you to know that your total compensation is made up of much more [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":1392,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-1390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=1390"}],"version-history":[{"count":4,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1390\/revisions"}],"predecessor-version":[{"id":1396,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/1390\/revisions\/1396"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/1392"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=1390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=1390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=1390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}