LSU Personnel started receiving phishing e-mails on October 11th, 2017 related to email validation.
Subjects of the Phishing e-mail - "Re-validate" and "ALERT"
Sender Name - Internal to LSU
Sender e-mail address - Internal to LSU
*Internal accounts can be compromised and used by malicious actors to send phishing e-mails, in order to appear more authentic.
Screenshot of phishing e-mail
Content of phishing e-mail
The content of the message is (Links and other descriptors have been removed for security purposes):
This is an automatic message by system to let you know that you have to confirm your account information. An Attempt has been made to login from a new computer, You might not be able to send or receive new mail until you re-validate your mailbox .To re-validate your mailbox.- CLICK HERE
Screenshot of phishing site
The URL provided in the e-mail does not belong to LSU, and directs the user to a third-party site. The third party site appears as below:
NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.