"wt" Phish

 

LSU Personnel started receiving phishing e-mails on March 6th, 2017 related to account validation due to mail quota being reached. The e-mail content was the same, but the subject line appears to be different in every e-mail.

Subjects of the Phishing e-mail - wt, et, ry, df, etc. (All subject line is a variation of 2 alphabets).

Sender Name - Internal LSU User

Sender e-mail address - Internal to LSU*

*Internal accounts can be compromised and used by malicious actors to send phishing e-mails, in order to appear more authentic.

The content of the message states the following (Links and other descriptors have been removed for security purposes):

PhishItem03062017-2-1

The URL provided in the e-mail does not belong to LSU and directs the user to a third-party site. The third party site appears as below:

PhishItem03062017-2

 

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.