Very similar to a job opportunity email in January. This phishing email made the round this weekend.
Images
**ALERT** Pay Schedule Changed – Today (4/14/2023, 7:53:39 PM)
Phishing message example:
Clues that it is a phishing message:
- The sender is not from HR or Payroll.
- The URL is for a non-SMU address.
- The email is pressuring with its sense of urgency.
- There is no signature or contact information.
Seeking Part-Time Personal Assistant Scam
Phishing message example:
Clues that it is a phishing message:
- While the sender is an SMU email account, normally, SMU employees do not send part-time job offers to other employees
- Generic greeting.
- The offer comes unsolicited.
- The recipient is directed to use a generic short link to apply
More Information
Here are a few ways to spot and avoid job scams from the FTC:
- Be suspicious if you’re offered a job without an interview. Scammers might say they’re out of town, too busy, or have another excuse for not talking to you by phone or in person.
- If you get a check before you start a job, it could be a scam. The person “hiring you” might say: it’s your first paycheck, to use the money to buy supplies, or – for caregivers hired online – that it’s for expenses related to caring for their loved one. But later, they’ll tell you to send part of the money to someone else or return it to them. They’ll have excuses, but the main thing to know is this: the check is fake. By the time the bank realizes it, the scammer has your money (if you sent it), and the bank will want you to repay the money you withdrew.
- Check out potential employers before giving them any sensitive information. Search online for their name, email address, phone number, and even the text of the message they sent. You might find that others have had bad experiences and been scammed by the same people, or in a similar way.
IT Notice – MY SMU Maintenance Phishing Attempt
Phishing message example:
Clues that it is a phishing message:
- The sender is not from OIT.
- The recipient is not listed directly, but blind copied.
- The URL is for a third-party URL shortener, which OIT does not use.
- The email is pressuring with its sense of urgency.
- There is no signature or contact information.
Piano “GIVEAWAY” Scam
Phishing message example:
Clues that it is a phishing message:
- There is way too many recipients.
- The valuable items are being given away for free, but you MUST pay to ship. No pick-up options.
- Google search shows similar scams.
“Mandatory Harassment Prevention for Employees” Phishing
Phishing message example:
Clues that it is a phishing message:
- The sender is not from a department that would normally send the message.
- This type of message would normally come from a department, such as HR and not a user is an unrelated department.
- The recipient is taken to a fake Outlook login page.
- The recipient is not listed directly, but blind copied.
- The URL is for for a PK domain, which SMU does not use.
- The email is pressuring with its sense of urgency.
- There is no signature or contact information.
“Personal assistance” for WHO Scam
Phishing Example:
KEEP THE SAME PASSWORD Phishing Attempt
Phishing message example:
Clues that it is a phishing message:
- The sender is not from OIT.
- The recipient is not listed directly, but blind copied.
- The URL is for Google Forms, which OIT does not use.
- The email is pressuring with its sense of urgency.
- There is no signature or contact information.