{"id":1188,"date":"2019-09-05T08:47:42","date_gmt":"2019-09-05T13:47:42","guid":{"rendered":"http:\/\/sites.augsburg.edu\/it\/?p=1188"},"modified":"2025-08-11T09:19:27","modified_gmt":"2025-08-11T14:19:27","slug":"phishing-reminder","status":"publish","type":"post","link":"https:\/\/sites.augsburg.edu\/it\/2019\/09\/05\/phishing-reminder\/","title":{"rendered":"Phishing reminder"},"content":{"rendered":"<h2>Spear Phishing<\/h2>\n<p>We&#8217;ve been noticing more questions recently about suspicious emails that look like phishing. These days we tend to see more &#8220;spear phishing&#8221; campaigns.\u00a0 &#8220;Spear phishing&#8221; is just a way of saying it&#8217;s a targeted phishing campaign. People are studying our website to see our organizational structure to figure out who are people in authority. Then they send an email pretending to be that person from a free account they created (not associated with Augsburg or Luther Seminary).<\/p>\n<p>These campaigns try to instill a sense of urgency from a person of authority needing help.\u00a0 These are techniques to try to lure you in and in the end get money from you.<\/p>\n<p>Here&#8217;s a recent example:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1189 size-full\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.26.19-AM.png\" alt=\"Hello, Are you available?\" width=\"485\" height=\"300\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.26.19-AM.png 485w, https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.26.19-AM-300x186.png 300w\" sizes=\"auto, (max-width: 485px) 85vw, 485px\" \/><\/p>\n<p>Notice the carefully crafted signature to make it appear to be from Provost Kaivola. But also notice the email address it is from\u00a0<strong><em>kaivola@my.com<\/em><\/strong>. That is not an institutional email address. That odd email address should be a red flag.<\/p>\n<p>The best course of action is to mark this as spam so Google will be more likely to block it. We see most of these getting blocked as they are becoming very common.<\/p>\n<p>If you did reply they will reply back saying that they are in a meeting and need your help with something important (sense of urgency).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1191 size-full\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.39.03-AM-1.png\" alt=\"I'm in a meeting right now and I need your help with something important. Can you? I will be waiting for your feedback\" width=\"649\" height=\"355\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.39.03-AM-1.png 649w, https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.39.03-AM-1-300x164.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>If you reply again they will ask for you to buy a gift card from some online store &#8212; we&#8217;ve seen iTunes and Steam recently &#8212; and they say they&#8217;ll reimburse you for it.\u00a0 Again they will say it is urgent. This is a script we&#8217;ve seen over and over with these spear phishing campaigns.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1193 size-full\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.42.42-AM.png\" alt=\"I need the you to help me get a steam card from the store right now, I will surely REIMBURSE you back today once I'm done with meeting. I don't know when re meeting will be rounding up. So I need your help urgently. If you can help out I will love to get your feedback.\" width=\"499\" height=\"371\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.42.42-AM.png 499w, https:\/\/sites.augsburg.edu\/it\/files\/2019\/09\/Screen-Shot-2019-09-05-at-8.42.42-AM-300x223.png 300w\" sizes=\"auto, (max-width: 499px) 85vw, 499px\" \/><\/p>\n<h2>What should you do?<\/h2>\n<ol>\n<li>If it seems fishy or odd, it is likely a scam. Mark it as spam so Google will be more likely to block it.<\/li>\n<li>If you&#8217;re truly not sure, contact the person directly by phone or institutional email address to confirm. Do not reply to the suspicious message.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Spear Phishing We&#8217;ve been noticing more questions recently about suspicious emails that look like phishing. These days we tend to see more &#8220;spear phishing&#8221; campaigns.\u00a0 &#8220;Spear phishing&#8221; is just a way of saying it&#8217;s a targeted phishing campaign. People are studying our website to see our organizational structure to figure out who are people in &hellip; <a href=\"https:\/\/sites.augsburg.edu\/it\/2019\/09\/05\/phishing-reminder\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Phishing reminder&#8221;<\/span><\/a><\/p>\n","protected":false},"author":37,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,3],"tags":[],"class_list":["post-1188","post","type-post","status-publish","format-standard","hentry","category-phishing","category-security"],"_links":{"self":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/comments?post=1188"}],"version-history":[{"count":8,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1188\/revisions"}],"predecessor-version":[{"id":1201,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1188\/revisions\/1201"}],"wp:attachment":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/media?parent=1188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/categories?post=1188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/tags?post=1188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}