{"id":825,"date":"2022-08-15T08:18:23","date_gmt":"2022-08-15T15:18:23","guid":{"rendered":"https:\/\/blogs.pugetsound.edu\/infosec\/?p=825"},"modified":"2022-08-15T08:20:53","modified_gmt":"2022-08-15T15:20:53","slug":"phishing-from-8-12-22-ups-out-of-date","status":"publish","type":"post","link":"https:\/\/blogs.pugetsound.edu\/infosec\/the-phish-tank\/825","title":{"rendered":"Phishing from 8\/12\/22: &#8220;UPS out of date&#8221;"},"content":{"rendered":"\n<p class=\"has-large-font-size\">Original Phishing Message<\/p>\n\n\n\n<p><strong><em>NOTE: If you received this message, simply delete it and do not click on any links. The message is not legitimate. <\/em><\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"454\" src=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/08\/8-12-22-ups-phish-1024x454.png\" alt=\"\" class=\"wp-image-826\" srcset=\"https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/08\/8-12-22-ups-phish-1024x454.png 1024w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/08\/8-12-22-ups-phish-300x133.png 300w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/08\/8-12-22-ups-phish-768x341.png 768w, https:\/\/blogs.pugetsound.edu\/infosec\/files\/2022\/08\/8-12-22-ups-phish.png 1202w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-large-font-size\">Tips for Detection<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts.<\/li><li>The email is not sent from an @pugetsound.edu address.<\/li><li>The entire body of the email is a hyperlinked image (instead of text) which should be suspicious. This is a method used by attackers to bypass email spam filters.<\/li><li>Though the hyperlinked text appears to be for a pugetsound.edu site, hovering over the link reveals that the true destination goes to the URL securehelpinfo[.]com. <\/li><li>Technology Services will not ask you to click a link to \u201cavoid login interruption.\u201d<\/li><\/ul>\n\n\n\n<p class=\"has-large-font-size\">Text of Phishing Message<\/p>\n\n\n\n<p><strong>From<\/strong>: mcdoashl[@]gvsu[.]edu<br><strong>Subejct<\/strong>: UPS out of date<\/p>\n\n\n\n<p>Your UPS account settings are out-of-date. To improve all student\/faculty\/staff account user experience, privacy policy update is required to avoid login interruption. <\/p>\n\n\n\n<p>Privacy Policy Action Required now<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original Phishing Message NOTE: If you received this message, simply delete it and do not click on any links. The message is not legitimate. Tips for Detection Notice the maroon caution banner prepended to the message. This banner is added on messages that match patterns of other phishing attempts. The email is not sent from [&hellip;]<\/p>\n","protected":false},"author":521,"featured_media":826,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[3],"class_list":["post-825","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-phish-tank","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/users\/521"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/comments?post=825"}],"version-history":[{"count":2,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/825\/revisions"}],"predecessor-version":[{"id":829,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/posts\/825\/revisions\/829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media\/826"}],"wp:attachment":[{"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/media?parent=825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/categories?post=825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.pugetsound.edu\/infosec\/wp-json\/wp\/v2\/tags?post=825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}