"<A User> as Shared a file with you Using One Drive​" Phish

 

LSU Personnel started receiving phishing e-mails on July 6th, 2018, related to an internal user sharing a file using One Drive.

Subject of the Phishing e-mail - <User's Full Name> as Shared a file with you Using One Drive

Sender Name - Internal to LSU*

Sender e-mail address - Internal to LSU*

*Internal accounts can be compromised and used by malicious actors to send phishing e-mails, in order to appear more authentic.

Screenshot of phishing e-mail

 Screenshot of Phish Mail

Content of phishing e-mail

The content of the message is (Links and other descriptors have been removed for security purposes):

Hello,

Please find attached the Look Ahead files for Friday July 6th,2018 
Open (Link)
Kindly let me have your opinion

 

Screenshot of phishing site

The URL provided in the e-mail does not belong to LSU, and directs the user to a third-party site. The third party site appears as below:

 Screenshot of Phish Site

NOTE: ALWAYS verify the URL provided in any e-mail and PLEASE NOTE that LSU will not ask you for your account information in such a fashion.