University of Southern California

“IT Service” phish 2013-11-09

Posted on by Robert

Many people at USC received the following phish. There are several signs that this was not a legitimate message:

  1. Many grammatical errors.
  2. Exceeding your mail quota will prevent new mail from being delivered, but does not require a password/account reset.
  3. First they say you need to reset your account, then they claim your account is “experiencing an unexpectedly termination”. Phish often use this tactic to scare people into responding.
  4. If you hover over the link you can see that the linked site is not a USC site: weaccountupdate.yolasite.com
  5. The Reply-To field is a non-USC address: omokaroboss@outlook.com

Screen Shot 2013-11-09 at 19.18.10

Comments are closed.