"Pay Receipt." Phish

 

LSU Personnel started receiving a phishing e-mail on January 25th, 2017 related to settlement receipt.

Subject of the Phishing e-mail - Pay Receipt.

Sender Name - Account.Settlements

Sender e-mail address - External from LSU.

The content of the message states the following (Links and other descriptors have been removed for security purposes):

Here's your settlement receipt. Your pay was sent out today.

Kindly let me know when you get this.

Thank you

The e-mail also contains an attachment. The attachment is malicious and requires a username and password. This message is designed to capture LSU personnel username and passwords. The attachment has a pop-up that looks like below. Please DO NOT share/enter the username and password on this page. Additionally, if you have provided your username and password, please change your passwords immediately.

 

PhishItem01252017