"Compliment of the Season" Phish

 

LSU Personnel started receiving phishing e-mails on January 2nd, 2018, related to account re-validation.

Subject of the Phishing e-mail - Compliment of the Season

Sender Name - Internal to LSU*

Sender e-mail address - Internal to LSU*

*Internal accounts can be compromised and used by malicious actors to send phishing e-mails, in order to appear more authentic.

The content of the message is (Links and other descriptors have been removed for security purposes):

Screenshot of message

 Screenshot of Phishing Mail

Content of the message

Dear ISU Student,

Your Mail Account quota has reached limit, You might not be able to send or receive new mail until you re-validate your mailbox. To re-validate your mailbox.-

Go ISU Verification Page

Screenshot of phishing page

The URL provided in the e-mail does not belong to LSU, and directs the user to a third-party site. The third party site appears as below:

 Screenshot of Phishing site

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.