{"id":488,"date":"2021-10-27T13:57:29","date_gmt":"2021-10-27T20:57:29","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=488"},"modified":"2021-10-27T13:57:30","modified_gmt":"2021-10-27T20:57:30","slug":"phishing-from-10-27-21-itpugetsound-edu-to-username","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/488","title":{"rendered":"Phishing from 10\/27\/21: &#8220;IT@pugetsound.edu to username&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please delete it as it is NOT legitimate. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"998\" height=\"426\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-tfa-phish.png\" alt=\"\" class=\"wp-image-489\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-tfa-phish.png 998w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-tfa-phish-300x128.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2021\/10\/10-27-21-tfa-phish-768x328.png 768w\" sizes=\"auto, (max-width: 998px) 100vw, 998px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> info[@]employeebonus2021[.]com<br><strong>Subject:<\/strong> IT[@]pugetsound[.]edu to [<em>username<\/em>]<\/p>\n\n\n\n<p>Security Alert From: IT[@]pugetsound[.]edu<\/p>\n\n\n\n<p>To: [<em>username<\/em>]@pugetsound.edu<\/p>\n\n\n\n<p>Severity: High<\/p>\n\n\n\n<p>Details: We have upgraded our server to a Two-Factor Authentication method. Henceforth, you will be required to input a code that will be sent to your phone before you can access your work email.<\/p>\n\n\n\n<p>To Activate TFA:<br>1] Go to pugetsound.edu portal below.<br>2] Verify your phone number to activate the TFA(Two-Factor Authentication).<\/p>\n\n\n\n<p>Access Portal Here<\/p>\n\n\n\n<p>Note: You must activate your TFA immediately you receive this email to avoid beeing locked out of your account.<\/p>\n\n\n\n<p>This email message and its attachments are for the sole use of the intended recipient or recipients and may contain confidential information. If you have received this email in error, please notify the sender and delete this message.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please delete it as it is NOT legitimate. Text of Phishing Message From: info[@]employeebonus2021[.]comSubject: IT[@]pugetsound[.]edu to [username] Security Alert From: IT[@]pugetsound[.]edu To: [username]@pugetsound.edu Severity: High Details: We have upgraded our server to a Two-Factor Authentication method. Henceforth, you will be required to input a code that [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":489,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=488"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/488\/revisions"}],"predecessor-version":[{"id":490,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/488\/revisions\/490"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/489"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}