{"id":752,"date":"2022-06-08T14:24:18","date_gmt":"2022-06-08T21:24:18","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=752"},"modified":"2022-06-08T14:49:30","modified_gmt":"2022-06-08T21:49:30","slug":"phishing-from-6-8-2022-account-settings","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/752","title":{"rendered":"Phishing from 6\/8\/2022: &#8220;account settings&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please delete it and DO NOT click on any links. This message is not legitimate. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"988\" height=\"500\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish.png\" alt=\"\" class=\"wp-image-753\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish.png 988w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-300x152.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-768x389.png 768w\" sizes=\"auto, (max-width: 988px) 100vw, 988px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"has-large-font-size\">Tips For Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts.<\/li><li>The entire body of the email is a hyperlinked image (instead of text) which should be suspicious. <\/li><li>Notice the stretched Puget Sound logo, the use of &#8220;PSU&#8221;, and the outdated text of the website. <\/li><li>Hovering over the image reveals that the link does not take you to a pugetsound.edu site.<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to a a site <em>harrison-wells[.]mykajabi[.]com <\/em>designed to collect your credentials. Never enter your username\/password on sites you do not recognize. If you entered any information on this page, please contact the Technology Service Desk as your password may be compromised. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"584\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-link-1024x584.png\" alt=\"\" class=\"wp-image-756\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-link-1024x584.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-link-300x171.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-link-768x438.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/06\/6-8-22-account-settings-phish-link.png 1373w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> sovajen[@]gvsu[.]edu<br><strong>Subject:<\/strong> account settings<\/p>\n\n\n\n<p>Your PSU account settings are out of date. To improve all student\/faculty\/staff account user experience, privacy policy update is required to avoid login interruption. <\/p>\n\n\n\n<p>Privacy Policy Action Required Now<\/p>\n\n\n\n<p>Visit [<em>link removed<\/em>]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please delete it and DO NOT click on any links. This message is not legitimate. Tips For Detection Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts. The entire body of the email [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":753,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-752","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=752"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/752\/revisions"}],"predecessor-version":[{"id":759,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/752\/revisions\/759"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/753"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}