{"id":800,"date":"2022-07-25T08:19:03","date_gmt":"2022-07-25T15:19:03","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=800"},"modified":"2022-07-25T08:34:31","modified_gmt":"2022-07-25T15:34:31","slug":"phishing-from-7-26-22-re-august-payroll-verification","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/800","title":{"rendered":"Phishing from 7\/25\/2022: &#8220;Re: August Payroll-Verification !&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, please delete it as it is NOT legitimate. If you clicked the link and entered any information, please contact the Service Desk as your password may be compromised.<\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"364\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-1024x364.png\" alt=\"\" class=\"wp-image-801\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-1024x364.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-300x107.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-768x273.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish.png 1170w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message.<\/li><li>This message came from Artlon.Ruiz[@]sweetwaterschools[.]org. Legitimate messages about payroll will come from Human Resources with an @pugetsound.edu address.<\/li><li>Notice the various grammatical (e.g. &#8220;Employee&#8217;s&#8221;) and wording oddities (e.g. &#8220;follow on-screen directive .&#8221;). <\/li><li>The link goes to an online form. Never enter your password on online forms &#8211; many attackers utilize legitimate form building services such as Google Forms\/Microsoft Forms\/JotForm. Even though the site is legitimate, submitting information on these forms goes back to the creator of the form &#8211; in this case, cybercriminals. <\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Where Did the Link Lead?<\/p>\n\n\n\n<p>The link led to an online form asking for your account credentials.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"631\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-1024x631.png\" alt=\"\" class=\"wp-image-804\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-1024x631.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-300x185.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-768x473.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-1536x946.png 1536w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link-1440x887.png 1440w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/07\/7-25-22-payroll-phish-link.png 1609w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From:<\/strong> Artlon.Ruiz[@]sweetwaterschools[.]org<br><strong>Subject:<\/strong> Re: August Payroll-Verification !<\/p>\n\n\n\n<p>All Staff\/Employee&#8217;s<\/p>\n\n\n\n<p>The Finance and Accounts Unit wishes to advise that payroll will be early for the month of August.<\/p>\n\n\n\n<p>As such, the Finance and Accounts Unit (Payroll) is requesting that all staff \/Employee Verification should be done:<br>Visit: access-payroll [<em>link removed<\/em>] and follow on-screen directive .<\/p>\n\n\n\n<p>Payroll Account Department.<br>Copyright \u00a9 2022, All rights reserved<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, please delete it as it is NOT legitimate. If you clicked the link and entered any information, please contact the Service Desk as your password may be compromised. Tips for Detection Notice the maroon caution banner prepended to the message. This message came from Artlon.Ruiz[@]sweetwaterschools[.]org. Legitimate [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":801,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=800"}],"version-history":[{"count":3,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/800\/revisions"}],"predecessor-version":[{"id":806,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/800\/revisions\/806"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/801"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}