Latest phishing email mimics Microsoft

PULLMAN, Wash. – Information Services is alerting students, faculty and staff to the latest phishing email circulating the WSU campus that is posing as Microsoft.

This is a fraudulent email and individuals should not respond or click on any of the links. The email message shows as from “2012 Microsoft <info@btconnect.com>” with the subject line “Webmail Account Update” and contains the following text, including typos:

Email User,

From 14/10/2012, you’ll be getting an even better email service. Because it’s powered by Microsoft® Office 365, you’ll have the Latest technology behind you. That includes more protection from spam and viruses. And you’ll get a bigger mailbox too.

WE are excited to bring you Microsoft technology, a new Email and Online Application Experience! Powered by Google, Microsoft gives you many benefits including:

Over 7GB of storage space more!

An Enhanced Online Email Interface

Online capabilities to create and edit documents, spreadsheets and presentations

Online Calendar for easy schedule organization These features (and more) are available to Microsoft Subscribers at no additional cost!

Just login into your account Now:

Email Upgrade Centre”immediately”

Before the upgrade, your primary account holder will need to make a few changes to your account settings by logging in to your email account centre . you need to do it before we upgrade your full access in our database, or you might not be able to send or receive emails for a while.

Any questions?

You can find out more about the upgrade at our email upgrade centre. If you’re not sure who your primary account holder is, or they’re not around, take a look at our FAQs. And if you need help, just ask our specialist upgrade support team.

LOGIN NOW WITHOUT DELAY:

Thanks for choosing our new update with Microsoft® Office 365.

Adam Larson

Managing Director, Microsoft®,

Here’s what to do

If you do not reply to the email, then you are fine; there’s nothing more you need to do. If you did click on the link, but didn’t enter any personal information, (such as your Network ID or password), then the phishers will not have your account information, and there’s nothing more you need to do.

However, if you responded to the phishing email and entered your Access ID or Network ID and password or any other personal information, the phishers will have collected that information. The IS Security Office recommends that you immediately change your password and contact the IS Help Desk at 509-335-4357 or helpdesk@wsu.edu.

How to spot a phishing email
  • Review and compare the “from” email address. Do you recognize it and does it match the company or entity referenced in the body of the email? If not, be suspicious.
  • Is there a link/URL embedded within the email asking you to click on it? Be wary, it will probably ask you for your login and password or it may even download malware onto your computer.
  • Phishers are getting very tricky mimicking official organizations, be cautious of any email asking you to click on a link or to supply your login and password.
Never respond

The IS Security Office recommends that you never respond to requests for personal information that may be contained in suspicious emails, voice messages, or text messages. It is best to assume any solicitation of personal information employing fraudulent methods, is not authentic.

Phishing is the act of attempting to acquire information such as usernames, passwords, and/or credit card details by masquerading as a trustworthy entity in an electronic communication.

For further assistance or questions please contact your departmental IT support staff or the Help Desk at 509-335-4357 or helpdesk@wsu.edu.