“IT Service” phish 2013-11-09
Many people at USC received the following phish. There are several signs that this was not a legitimate message:
- Many grammatical errors.
- Exceeding your mail quota will prevent new mail from being delivered, but does not require a password/account reset.
- First they say you need to reset your account, then they claim your account is “experiencing an unexpectedly termination”. Phish often use this tactic to scare people into responding.
- If you hover over the link you can see that the linked site is not a USC site: weaccountupdate.yolasite.com
- The Reply-To field is a non-USC address: email@example.com