Main menu (IT)

Phishing Examples 2016


Mailbox Helpdesk

---Start of Email---

Reported: May 14, 2016
Email:
Date: Saturday, May 14, 2016
Subject: Mailbox Helpdesk

Dear Staff(s). (1)

New security updates need to be performed on our servers,due to the rate of phishing. Please CLICK HERE (link has been removed) (1) and sign in to the IT Help server for maintenance and update of your mailbox.

If your mailbox is not updated soon, Your account will be inactive and cannot send or receive messages. (3)

On behalf of the IT department, this IT Alert Notification was brought to you by the Help Desk Department. This is a group email account and its been monitored 24/7, therefore, please do not ignore this notification, because its very compulsory.

Sincerely,

IT Department (2)

©2016 Microsoft outlook. All rights reserved. (4)

---End of Email---

  1. It's ironic that an email about phishing could be used for phishing. Note the lack of a personal greeting. Also note that the user is immediately asked to CLICK HERE before anything has really been explained. 
  2. The email has been sent by the "IT Department" which is very vague and not from the IT Help Center and includes no contact information. 
  3. The finality of the email should raise some suspicion. Most of our email campaigns will have multiple emails leading up to the “final” notification.
  4. In the signature line, the "outlook" portion of Microsoft Outlook is not capitalized. This is a red flag.