"VALIDATE YOUR OFFICE EMAIL" Phish

 

LSU Personnel started receiving phishing e-mails on July 10th, 2017 related to restoring email access due to storage limit issues.

Subject of the Phishing e-mail - VALIDATE YOUR OFFICE EMAIL

Sender Name - External to LSU

Sender e-mail address - External to LSU

Screenshot of phishing e-mail

 Screenshot of Phish Mail

Content of phishing e-mail

The content of the message states the following (Links and other descriptors have been removed for security purposes):

Office Email!
Your email address has been disabled because we are unable to validate your office email . 
Validate your Office email address below to guide you against any malicious messages.

Validate Your Office Email Address

MAIL 365 ADMINISTRATOR
Web Administrator
 
Judicial Affairs
 
webmaster@microsoft.com

Screenshot of phishing site

The URL in the e-mail redirects user to a website that does appear to be similar to Microsoft Office365 page, the URL does not belong to LSU or Microsoft. The third party site appears as below:

Screenshot of Phish Site

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.