"Your Password Expires Today" Phish

 

LSU Personnel started receiving phishing e-mails on June 20th, 2017 related to password expiration and updating password.

Subject of the Phishing e-mail - Your Password Expires Today

Sender Name - External to LSU

Sender e-mail address - External to LSU

Screenshot of phishing e-mail 

Screenshot of Phish Mail

Content of phishing e-mail

The content of the message states the following (Links and other descriptors have been removed for security purposes):

System Administrator

Your password will expire in a few days time. Kindly click on the Help Desk to update your current password and automatically upgrade to the most recent e-mail Outlook Web Apps 2017.

If the password is not been updated today, your account will be suspended within 12 hours.

System Administrator,

Connected to Microsoft Exchange.

© 2017 All rights reserved Microsoft Corporation.

Screenshot of phishing site

The URL provided in the e-mail does not belong to LSU or Microsoft, and directs the user to a third-party site. The third party site appears as below:

Screenshot of Phish Site

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.