Go to the U of M home page

Thursday, February 26, 2015

Phishing Example 86: Important Account Information

Received February 2015

*Dear User*,

You are required to update your The University of Minnesota account
information due to recent update in our database. Please follow the link
below to update your account information.

The University of Minnesota Database Account Update
<hxxp://xxxxxxx.xxx/zoro/>

Regards,

The University of Minnesota


Notes:

  • Very good copy of UMN login page
  • URL is hosted in .pl (Poland) domain - NOT umn.edu.
  • Filling in form pushes you to the REAL login page - likely people with think they "fatfingered" their password and type it correctly and complete a normal login.

Wednesday, February 18, 2015

Advisory: IRS Issues Warning for a Scam Targeting Tax Preparers


National Cyber Awareness System:
02/18/2015 09:46 PM EST

Original release date: February 18, 2015
The Internal Revenue Service (IRS) has issued a press release addressing a new spear phishing scam targeting tax preparers and other tax professionals. Scam operators often use fraudulent e-mails to entice their targets to reveal login credentials.
US-CERT encourages users and administrators to review the IRS press release for details and refer to US-CERT Security Tip ST15-001 for information on "tax" themed phishing attacks.

Thursday, February 5, 2015

Phishing Example 85: KINDLY REVIEW THE ATTACHED DOCUMENTS!!!

Received February 2015

Here's another fake Google Document -

Subject:KINDLY REVIEW THE ATTACHED DOCUMENTS!!!
Date:Thu, 5 Feb 2015 17:56:45 +0200
To:undisclosed-recipients:;
From:
Hello,

I tried to get these document across to you before. Did you ever get
it? VIEW HERE <hxxp://www.xxxxxxxxxx.gm/govt/google> and sign on with your
email to access it as attached on Google.doc, get back to me so we can
discuss.
Regards


Not at all like a real Google login - includes too big a variety of email services for "login."

Like other examples, they really do go to a "document":