{"id":288,"date":"2021-02-24T08:46:15","date_gmt":"2021-02-24T16:46:15","guid":{"rendered":"http:\/\/blogs.pugetsound.edu\/infosec\/?p=288"},"modified":"2021-02-24T08:54:19","modified_gmt":"2021-02-24T16:54:19","slug":"phishing-email-from-2-24-21-re-it-services-department","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/288","title":{"rendered":"Phishing Email from 2\/24\/21: &#8220;Re: IT Services Department&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message, please simply delete the message. Do not click any links and do not enter or reply with any information<\/em>. <\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"409\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-email-data-1024x409.png\" alt=\"\" class=\"wp-image-289\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-email-data-1024x409.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-email-data-300x120.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-email-data-768x307.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-email-data.png 1156w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the &#8220;Caution&#8221; banner that was applied to the top of the message. Technology Services adds the banner on emails that match patterns of previous phishing attempts. <\/li><li>The sending email address is from the cornwallhospital[.]ca domain. This is not a Puget Sound address. <\/li><li>Technology Services will not ask you to click a link to protect your email or to upgrade your email. <\/li><li>The display name &#8220;Barretto, Dawn&#8221; versus the name in the email signature &#8220;Josselin Issabelle&#8221; do not match. Further, neither individuals work at the university. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where did the link lead?<\/p>\n\n\n\n<p>The link led to a fraudulent Outlook sign in page. <strong><em>Note: If you entered your credentials on this page, please immediately change your password and contact the Service Desk at x8585. Your credentials are likely compromised. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"397\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-1-1024x397.png\" alt=\"\" class=\"wp-image-291\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-1-1024x397.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-1-300x116.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-1-768x298.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/02\/2-24-21-IT-phish-1.png 1401w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p>From: Dawn.Barretto[@]cornwallhospital[.]ca<br>Subject: IT Services Department<\/p>\n\n\n\n<p>All our Outlook Users are at risk today.<\/p>\n\n\n\n<p>You were contacted by the IT Services Department In an approach to Protect our Email Data, which you ignored. We received a severe unsolicited message sent in bulk to all our outlook Users. Please secured your email NOW with our new anti-Spam Mailinblack, for your mail to be delivered, please Protect your email now by visiting our anti-Spam Mailinblack Portal at https:\/\/app[.]getresponse[.]com\/site2\/dawnbarretto\/?u=QvzCa&amp;webforms_id=zZIsP and install the anti-Spam Mailinblack Software.<\/p>\n\n\n\n<p>Regards,<br>Josselin issabelle<br>IT Service Desk Support<br>IT-Support Analyst<br>Information Technology Services DEPT.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, please simply delete the message. Do not click any links and do not enter or reply with any information. Tips for Detection Notice the &#8220;Caution&#8221; banner that was applied to the top of the message. Technology Services adds the banner on emails that match patterns of [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":289,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3,4],"class_list":["post-288","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing","tag-phishtank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/288","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=288"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/288\/revisions"}],"predecessor-version":[{"id":294,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/288\/revisions\/294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/289"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=288"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=288"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=288"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}