Go to the U of M home page

Monday, January 11, 2016

Phishing Example 120: Your Paperless W2

Received January 2016

From: ESSW2@@umn.edu <<--NOTE ODD "@@" address
Date: Mon, Jan 11, 2016 at 1:52 PM
Subject: Your Paperless W2

Dear: Account Owner,

Our records indicate that you are enrolled in the University of Minnesota paperless W2 Program. As a result, you do not receive a paper W2 but instead receive e-mail notification that your online W2 (i.e. "paperless W2") is prepared and ready for viewing.

Your W2 is ready for viewing under Employee Self Service. Logon at the following link:

Click Here to Logon <<link to offshore non-umn address>>

If you have trouble logging in to Employee Self Service at the link above, please contact your Payroll Department for support.

If you would like to un-enroll in the Paperless W2 Program, please logon to Employee Self Service at the link above and go to the W2 Delivery Choice webpage and follow the instructions.

Anyone who did reply to this with their account information should reset their password and account secrets immediately.

The fake login looks like this:

Fake UMN login page from kaizenkz.org

Note: Firefox, Chrome and IE all attempt to protect you from going to this link:


IE browser warning
Chrome browser warning
Firefox browser warning

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.