{"id":629,"date":"2022-02-10T09:21:26","date_gmt":"2022-02-10T17:21:26","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=629"},"modified":"2022-02-10T11:58:25","modified_gmt":"2022-02-10T19:58:25","slug":"phishing-from-2-10-2022-re-payroll-earning-statement","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/629","title":{"rendered":"Phishing from 2\/10\/2022: &#8220;RE: Payroll Earning Statement&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please simply delete it as it is NOT legitimate. Do not click on the link. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"997\" height=\"454\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish.png\" alt=\"\" class=\"wp-image-631\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish.png 997w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-300x137.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-768x350.png 768w\" sizes=\"auto, (max-width: 997px) 100vw, 997px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Emails containing threats to withhold payment or terminate your account and asking you to click a link to verify your email are generally not legitimate. A sense of urgency is common in phishing emails.<\/li><li>Notice the maroon &#8220;Caution&#8221; banner prepended to the message. Messages with this banner match patterns of other phishing emails. <\/li><li>The sender of this email it outside the university. <\/li><li>Legitimate messages from Human Resources will come from an @pugetsound.edu address. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a fake Outlook Web App log in page on betimar[.]com\/OWA\/. Do not enter your credentials on sites you do not recognize. Remember, the website to log in to your Puget Sound email is webmail.pugetsound.edu. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"617\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-link-1-1024x617.png\" alt=\"\" class=\"wp-image-632\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-link-1-1024x617.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-link-1-300x181.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-link-1-768x463.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/02\/2-10-22-payroll-phish-link-1.png 1045w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From: <\/strong>sheree.henton[@]bisd[.]net<br><strong>Subject:<\/strong> RE: Payroll Earning Statement<\/p>\n\n\n\n<p>Your Earning Statement for the month of February is attached in the link below. All staff &amp; employees are expected to verify their email account for a new payroll directory and adjustments for the month of February. Kindly Click Earning-Statement and complete the required directive to avoid &#8216;Hold&#8217; of your benefit payment for February 2022.<\/p>\n\n\n\n<p>Thank you,<br>Payroll Admin Department.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please simply delete it as it is NOT legitimate. Do not click on the link. Tips for Detection Emails containing threats to withhold payment or terminate your account and asking you to click a link to verify your email are generally not legitimate. A sense of [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":631,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=629"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/629\/revisions"}],"predecessor-version":[{"id":643,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/629\/revisions\/643"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/631"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}