Showing posts with label fraudulent emails. Show all posts
Showing posts with label fraudulent emails. Show all posts

Tuesday, February 9, 2016

Fraudulent Email and Phishing Redux

Example of phishing email (click to enlarge)
Yet another round of fraudulent "phishing" emails have been sent across Campus masquerading as an official email warning users that their accounts are about to be shut down unless they are verified.

As we have noted multiple times during these campaigns, the Help Desk will never solicit your account information. All of our account work is done via our ePass website [epass.plu.edu], and we will not intentionally put your account into a position where it cannot be recovered.

Given how these emails continue, we felt it would be appropriate to pass on a small FAQ to help better inform the PLU community about these phishing emails.

Summary

  • PLU (I&TS) will never solicit your account information via email
  • If you ever have even the slightest inkling that an email might be fraudulent, do not do anything with it and call the Help Desk at 253-535-7525
  • If you have clicked on any links in these emails or responded to them, call the Help Desk at 253-535-7525
  • This phishing campaign has been attacking users for several months, taking over PLU accounts and sending more phishing emails from PLU accounts
  • They often include PLU logos to mimic official PLU emails and claim to be from the non-existent PLU Webmail Management Team

FAQ

Q: What exactly is a phishing email?
A:  A phishing email is basically an email meant to trick users into revealing sensitive information, "baiting" them into giving out private info such as passwords, credit card information, etc.

Typically, a phishing email will masquerade as coming from an official source, often claiming to either have important information for the user or claiming that their "account will be terminated" if the user doesn't give out their password information.

Unfortunately, methods will vary from phishing email to phishing email.

Q: How can I tell if an email is a phishing email?
A: Most phishing emails are plagued with:
  • Spelling errors
  • Grammatical mistakes
  • Strange use of punctuation
  • Bits of "code" showing in the email
  • Vague claims or threats towards your account
  •  Inconsistent or incorrect information about the account system
Q: Why is this still happening months after the initial email?  Can't these emails be stopped?
A:  The way this particular phishing campaign is working is to send out as many emails as possible to PLU emails, collect a few accounts, sit on these accounts for a bit while sending out more emails, and continue to collect more accounts.  Every time the attackers get another account, they can send out hundreds of emails; if even one person responds, that's another account and another couple hundred emails.

It's a vicious cycle that we can only break by educating users about the existence of these emails.  While we do our best to shut down the accounts as soon as we receive a report, usually we don't get a report until after a few minutes of sending, which can be hundreds of emails by that point.

We are considering other alternatives system side, but we need to be vary careful about such alterations as they can affect the receiving of legitimate emails as well.

Q: What do the attackers have to gain by doing this?
A:  Just more sources to spam people with.  Once the spammers have a sufficient number of accounts stocked up, they can start sending out spam emails to other people.  Often times we will cleanse an account and find that it has been altered to look like a bank or a school or a credit union.

Q: What should I do if I have responded to one of these emails?
A:  Change your password immediate by going to epass.plu.edu [epass.plu.edu] and call the Help Desk at 253-535-7525.  We will need to walk you through cleaning your account to ensure that no one else has access.

Q:  Is there anything I can do to help combat these emails?
A:  Yes!  Continue to report them to us every time you get one.  It may seem futile or redundant, but the sooner we know about a new wave, the sooner we can take action.

Tell your colleagues and friends about the phishing emails and about how they can learn more about them; the more people that know, the better chance we have that the phishing waves will be ineffective.

Monday, September 9, 2013

Spam Report 9/9/2013

At approximately 2:00 pm today, the Help Desk received reports of a spam email offering money for survey taking.  A screenshot of the email text is attached to this post.

While this is different than the usual phishing emails we receive, we are posting a warning on this because it's very important to be able to identify and avoid scam emails.  Often times scammers will send out enticing emails offering vast sums of money for little to no work; in cases like these, the old adage applies:  If it sounds too good to be true, it probably is.

If you have already responded to the email, please discontinue all communication immediately.  If you have provided personal information, such as your bank account information, please contact your Bank immediately and discuss the issue, they will advise you on the proper procedure for protecting your accounts.

If you have given out any password or log in information, please follow our standard procedures for possibly compromised accounts:
  • Update your epass password at http://epass.plu.edu
  • Update your password on any sites where you used that password (i.e., if your epass was the same as your bank password, update your bank password as well)
  • Log into your Gmail and sign out of all other sessions; to do this, scroll down to the bottom of the page and look for the section which says "Last Account Activity"; click on the "Details" link; a window will appear which will let you force sign out all other sessions.
Any questions, please contact the Help Desk at 253-535-7525 or helpdesk@plu.edu.  You can also stop in at the Help Desk located on the first floor of the Library.

-D.D.

Example of too good to be true.  Click to enlarge

Thursday, August 29, 2013

Spam Report 8/29/13

At approximately 6:30 pm on August 28th, a wave of spam emails went out to many users on campus.  The Help Desk began receiving reports this morning of the email.  At the bottom of this post is a write up of how we determined this email to be fraudulent.

As always, whenever you receive a message you think might be a phishing email, err on the side of caution and ignore it.  If you ever aren't sure, call the Help Desk at 253-535-7525, and we will be glad to help confirm or deny it.

If you responded to the email and provided any information, please do the following:
  • Update your epass password at http://epass.plu.edu
  • Update your password on any sites where you used that password (i.e., if your epass was the same as your bank password, update your bank password as well)
  • Log into your Gmail and sign out of all other sessions; to do this, scroll down to the bottom of the page and look for the section which says "Last Account Activity"; click on the "Details" link; a window will appear which will let you force sign out all other sessions.
If you need assistance with any of these steps or have questions about the phishing email, please contact the Help Desk at 253-535-7525 or email us at helpdesk@plu.edu.


Our analysis of the email (Click to Enlarge)
 

Wednesday, June 5, 2013

Spam/Phishing Email Report 6/5/13

This afternoon, the Help Desk began receiving reports of a new spam/phishing email going around the PLU domain.  The original email, as well as a mark up explaining what identifies it as a phishing email, can be found at the bottom of this post.

As always, whenever you receive a message you think might be a phishing email, err on the side of caution and ignore it.  If you ever aren't sure, call the Help Desk at 253-535-7525, and we will be glad to help confirm or deny it.

If you responded to the email and provided any information, please do the following:
  • Update your epass password at http://epass.plu.edu
  • Update your password on any sites where you used that password (i.e., if your epass was the same as your bank password, update your bank password as well)
  • Log into your Gmail and sign out of all other sessions; to do this, scroll down to the bottom of the page and look for the section which says "Last Account Activity"; click on the "Details" link; a window will appear which will let you force sign out all other sessions.
If you need assistance with any of these steps or have questions about the phishing email, please contact the Help Desk at 253-535-7525 or email us at helpdesk@plu.edu.


How did we know this was a phishing email?  Click to enlarge 
and read how!

Friday, April 5, 2013

Spam email report 4/5/2013

At approximately 12:00 pm today, the Help Desk began receiving reports of a spam email message being sent to users at PLU, claiming to be from the I&TS Help desk.  A copy of the spam message will be included at the bottom of this post.

As always, I&TS will never request your password; any emails claiming to be from I&TS or from the Help Desk claiming you need to email your password are fraudulent.  If you are ever not sure if a message is legitimate or not, always err on the side of caution, and contact the Help Desk at 253-535-7525 or e-mail us at helpdesk@plu.edu.  We will be more than glad to help determine if a message is legitimate or not.


If you accidentally responded to one of these messages, please go to http://epass.plu.edu and use the Change Your ePass Password link to change your password immediately.  Please contact the Help Desk if you need assistance updating your password.


---Spam Message---
From: IT Helpdesk <helpdesk@heldesk.edu> <kbrown@eureka.edu>
Date: Fri, Apr 5, 2013 at 12:38 PM
Subject: Important! 2013 Webmail Upgrade to Prevent Email Account Deletion
To:


Dear Edu Webmail User,

This message is from IT Help Desk to all our email Users. We are
upgrading to a new email version to help increase the storage megabyte
and are therefore deleting all unused email account as a result of the
non-existence of users as well as updating our university directory

Also be informed of the serious technical difficulty at hand. Our
Webmail Database that records your webmail data and profile has just
been contrasted by a serious circulating internet virus which may make
you lose your contacts. As a result we are upgrading to a new email
version to help increase the storage megabyte and are therefore
deleting all unused email account as a result of the non-existence of
users.

To confirm the your account is currently in use and to integrate the
recent maintenance carried out in e-mail system and also help in
resetting your space in our database and erase the virus circulating
our webmail. Reply back with the information as required below;

Username/Account ID:...
Password:...
Faculty/Department:....
Email:......

Warning! Webmail owner that refuses to update their account by
providing the requested details above after reading this mail will
loose his / her account permanently.

Account Alert Code: X3XX00178SU
Thank you for using our Webmail

IT Help Desk
Computing & Communications

Copyright (c) 2013. All Rights Reserved.

---End Spam Message---

Thursday, September 2, 2010

Fraudulent Emails

From time to time you are likely to receive email messages asking for your PLU email account password. These messages claim to have been sent from a PLU tech support address, but they are in fact fraudulent attempts (often called phishing scams) to obtain your login information. 

PLU will NEVER ask you to reveal your password or other such personal information via email! Never share your password with anyone, ever.  If you have questions about the authenticity of emails, contact the Help Desk at helpdesk@plu.edu or 253-535-7525. 

For information, check out the Cyber Safety page which contains links to examples of these kinds of fraudulent emails.