{"id":477,"date":"2021-10-27T09:27:56","date_gmt":"2021-10-27T16:27:56","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=477"},"modified":"2021-10-27T09:28:54","modified_gmt":"2021-10-27T16:28:54","slug":"phishing-from-10-27-2021-reminder-your-pugetsound-email-and-o365-password-will-expired-in-5-days","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/477","title":{"rendered":"Phishing from 10\/27\/2021: &#8220;REMINDER: YOUR pugetsound Email and O365 Password will expired in 5 days&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>Note: If you received this message, please delete it and do NOT click on any links. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"421\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-1024x421.png\" alt=\"\" class=\"wp-image-478\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-1024x421.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-300x123.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-768x316.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-1536x632.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish-1440x593.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-password-phish.png 1888w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the caution banner added to the message. <\/li><li>&#8220;Puget Sound&#8221; is spelled &#8220;pugetsound&#8221; throughout the message.<\/li><li>Technology Services will never ask you to click a link to keep your password<\/li><li>The links in the email lead to a Google Cloud Storage link which would not be where you manage your Puget Sound password. Beware of cloud file sharing links in emails you are not expecting as they may download malware onto your device.<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>pugetsound Password Notification &lt;<em>username<\/em>@pugetsound.edu&gt;<br><strong>Subject: <\/strong>REMINDER: YOUR pugetsound Email and O365 Password will expired in 5 days<\/p>\n\n\n\n<p>REMINDER: YOUR pugetsound Email and O365 Password will expired in 5 days. | View this email in your browser.<\/p>\n\n\n\n<p>Password Update Notice.<br>User ID: [<em>username<\/em>]@pugetsound.edu<\/p>\n\n\n\n<p>Hello,<\/p>\n\n\n\n<p>Our records indicate that your password for pugetsound account has expired and you have not yet enrolled in \u201cPassword Help.\u201d Please take a moment to enroll now, and you can then reset a forgotten or expired PC \/ E-mail password at any time.<\/p>\n\n\n\n<p>KEEP PASSWORD<\/p>\n\n\n\n<p>You can only update your password via this link for 12 hours after receiving this email.<\/p>\n\n\n\n<p>PASSWORDHELP[@]pugetsound.edu.<\/p>\n\n\n\n<p>This is a mandatory service communication. To set your contact preferences for other communications, visit the pugetsound email communications manager.<\/p>\n\n\n\n<p>This message was sent from an unmonitored e-mail address. Please do not reply to this message.<br>Privacy | Legal<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message Note: If you received this message, please delete it and do NOT click on any links. Tips for Detection Notice the caution banner added to the message. &#8220;Puget Sound&#8221; is spelled &#8220;pugetsound&#8221; throughout the message. Technology Services will never ask you to click a link to keep your password The links in [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":478,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-477","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/477","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=477"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/477\/revisions"}],"predecessor-version":[{"id":480,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/477\/revisions\/480"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/478"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=477"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}