{"id":625,"date":"2022-02-09T13:30:58","date_gmt":"2022-02-09T21:30:58","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=625"},"modified":"2022-02-09T13:31:32","modified_gmt":"2022-02-09T21:31:32","slug":"phishing-from-2-9-2022-service-help-desk","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/625","title":{"rendered":"Phishing from 2\/9\/2022: &#8220;Service Help Desk&#8221;"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Original Phishing Message<\/h2>\n\n\n\n<p><em>If you received this message, please delete it as it is NOT legitimate. Do NOT click the link or submit any information.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"117\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image.png\" alt=\"\" class=\"wp-image-626\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image.png 640w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-300x55.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Tips for Detection<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Legitimate emails regarding your Puget Sound password will come from <strong>ts-no-reply@pugetsound.edu<\/strong>. You will receive more than two days notice on an impending password expiration, and you&#8217;ll <strong>never <\/strong>be contacted by an individual from Technology Services about your password.<\/li><li>This sender is an individual from outside the university &#8212; note the sending address. <\/li><li>This email contains grammatical errors and typos with no forms of contact. Official TS emails will include our email and extension.<\/li><li>The link added to the message does not lead to a Puget Sound site, but rather an online form. <\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Where Did the Link Lead?<\/h2>\n\n\n\n<p>The link goes to a form on share[.]hsforms[.]com, and prompts you for your username, email, password, and a password confirmation. Never submit passwords on any form. <br><br>Users should note the suspicious formatting of the word &#8220;password,&#8221; likely as an attempt to evade automatic spam protection. <br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-1024x512.png\" alt=\"\" class=\"wp-image-627\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-1024x512.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-300x150.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-768x384.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-1536x768.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1-1440x720.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/image-1.png 1908w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message If you received this message, please delete it as it is NOT legitimate. Do NOT click the link or submit any information. Tips for Detection Legitimate emails regarding your Puget Sound password will come from ts-no-reply@pugetsound.edu. You will receive more than two days notice on an impending password expiration, and you&#8217;ll never [&hellip;]<\/p>\n","protected":false},"author":635,"featured_media":626,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-625","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/635"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=625"}],"version-history":[{"count":1,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/625\/revisions"}],"predecessor-version":[{"id":628,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/625\/revisions\/628"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/626"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}