"Microsoft Outlook Update" Phish

 

LSU Personnel started receiving phishing e-mails on May 2nd, 2017 related to a new Outlook Web App.

Subjects of the Phishing e-mail - Microsoft Outlook Update

Sender Name - External to LSU

Sender e-mail address - External to LSU (@lagcc.cuny.edu)

Screenshot of phishing e-mail

 screenshot of Phish Mail

Content of phishing e-mail

The content of the message states the following (Links and other descriptors have been removed for security purposes):

Welcome to the new outlook web app for Staff and Students
The new Outlook Web app for Staff/Student is the new home for online self-service and information.

Click here on new outlook web access portal and login to:

·                     access the new staff/student directory
·                     access your pay slips and P60s
·                     update your ID photo
·                     look up student records using the contact search facility
·                     use our quick links at the bottom of each page to help you find relevant tools and information about upcoming events.

Screenshot of phishing site

The URL provided in the e-mail does not belong to LSU and directs the user to a third-party site. The third party site appears as below:

screenshot of Phish Site

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.