Monday, November 10, 2014

University "Accept your new raise" Phish

One of the best emails that an employee can get from their employer is the one that tells you that you have been awarded a raise! In certain industries, such as academia, this type of email is quite rare, so you can imagine what welcome news it would be!

University Salary Phish Example

Phishers have been attacking universities across the country with emails that look like this one (Example email from University of Chicago):

++++++++++++++++++++++

From: employeebenefits@uchicago.edu
Subject: Your Salary Raise Confirmation

Hello,

The University is having a salary increase program this year with an average of 2.5%.
The Human Resources department evaluated you for a raise on your next paycheck.
Click below to confirm and access your salary revision documents:

Click Here hxxp://kirovtourism.ru/www.uchicago.edu/Sign-In.htm to access the documents

Sincerely,
Human Resources
The University of Chicago

++++++++++++++++++++++

Recent reports about Your Salary Raise Confirmation

A google search for that email subject "Your Salary Raise Confirmation" helps to reveal just how many Universities are targeted in this attack.

DHS / REN-ISAC / Multi-State ISAC Advisory

On August 18, 2014, the Department of Homeland Security released an advisory titled "University Payroll Theft Scheme" that cautioned Universities to be wary of this scheme.

Some of the email subjects that were mentioned in that advisory include:

  • Your Salary Review Documents
  • Important Salary Notification
  • Your Salary Raise Confirmation
  • connection from unexpected IP
  • RE: Mailbox has exceeded its storage limit.
According to the DHS advisory, this scam has been seen repeatedly at a number of universities dating back to at least August of 2013!

If you receive a copy of a phish such as this, please send an alert to: soc@ren-isac.net

No comments:

Post a Comment

Trying a new setting. After turning on comments, I got about 20-30 comments per day that were all link spam. Sorry to require login, but the spam was too much.