{"id":232,"date":"2017-07-21T11:18:42","date_gmt":"2017-07-21T11:18:42","guid":{"rendered":"https:\/\/blog.bham.ac.uk\/itsecurity\/?p=232"},"modified":"2018-11-02T11:16:08","modified_gmt":"2018-11-02T11:16:08","slug":"important-message-from-staff-portal","status":"publish","type":"post","link":"https:\/\/blog.bham.ac.uk\/itsecurity\/2017\/07\/21\/important-message-from-staff-portal\/","title":{"rendered":"Important Message From Staff Portal"},"content":{"rendered":"<p>We have a huge number of reports of a phishing campaign which many people have recognised as such.\u00a0 Some, however, appear to have been taken in by this.\u00a0 Initial versions came from outside the University which were easy to spot as bogus.<\/p>\n<p>However,\u00a0 once some people had given their passwords away their accounts were then used to send the messages.\u00a0 As these came from University staff members some recipients trusted them.\u00a0 I would like to remind everyone that IT Services does not\u00a0 pick random staff from random departments to send out messages on our behalf.<\/p>\n<p>Here is an example which has been anonymised.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-233\" src=\"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1.jpg\" alt=\"Example of phishing email\" width=\"1185\" height=\"691\" srcset=\"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1.jpg 1185w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1-300x175.jpg 300w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1-768x448.jpg 768w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1-1024x597.jpg 1024w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal1-250x146.jpg 250w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Clicking on the link will load the following page.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-234\" src=\"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2.jpg\" alt=\"Picture of copy of portal web page\" width=\"1277\" height=\"749\" srcset=\"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2.jpg 1277w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2-300x176.jpg 300w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2-768x450.jpg 768w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2-1024x601.jpg 1024w, https:\/\/blog.bham.ac.uk\/itsecurity\/wp-content\/uploads\/sites\/36\/2017\/07\/portal2-250x147.jpg 250w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>This is a copy of our staff portal page.\u00a0 However, the address in the address bar at the top indicates that it is not our portal page.\u00a0 IT services does not send unsolicited emails linking to pages where you have to login, so even without the incorrect address it should be clear at this point that something is wrong.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have a huge number of reports of a phishing campaign which many people have recognised as such.\u00a0 Some, however, appear to have been taken in by this.\u00a0 Initial versions came from outside the University which were easy to spot as bogus. However,\u00a0 once some people had given their passwords away their accounts were then &hellip; <a href=\"https:\/\/blog.bham.ac.uk\/itsecurity\/2017\/07\/21\/important-message-from-staff-portal\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Important Message From Staff Portal&#8221;<\/span><\/a><\/p>\n","protected":false},"author":84,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,3,13,1],"tags":[],"class_list":["post-232","post","type-post","status-publish","format-standard","hentry","category-malicious-email","category-examples-of-malicious-email","category-phishing","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/posts\/232","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/users\/84"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/comments?post=232"}],"version-history":[{"count":4,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/posts\/232\/revisions"}],"predecessor-version":[{"id":238,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/posts\/232\/revisions\/238"}],"wp:attachment":[{"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/media?parent=232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/categories?post=232"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.bham.ac.uk\/itsecurity\/wp-json\/wp\/v2\/tags?post=232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}