Visit the Pennsylvania State University Home Page

Stop Phishing Scams

The Latest Phishes Sent to Penn Staters

  • Office of Information Security
  • Phishing Home
  • What Is Phishing?
  • How to Report a Phish

Archives for August 2016

abc123@psu.edu 2 new Blackboard messages from IT Admin

August 23, 2016 by Paul Carlisle Kletchka

From: Pennsylvania State University I Blackboard <xxxxxx@uconn.edu>
Date: Tuesday, August 23, 2016 at 10:37 AM
To: <xxxxxx@psu.edu>
Subject: xxxxxx@psu.edu 2 new Blackboard messages from IT Admin

Dear xxxxxx@psu.edu,

You have 2 new messages from your University Technology Admin

posted to you through the Blackboard Learning System.

www.blackboard.com/blackboard/course/messagecenterxxxxxx@psu.edu36344331 (<– Link leads to a fake Blackboard login page)

Regards,
MY  UNIVERSITY.
Admin Management

Phish from August 23, 2016 at 10:37 a.m.

This phishing message gives the impression that Penn State uses Blackboard for its LMS and there are messages waiting there for the recipient. However, Penn State uses Canvas and ANGEL, so that is one clue this is a bogus message. Additionally, the “from” address is a UConn email address, whereas a message about a central Penn State service would come from an official Penn State address. The link that is shown in the message is not the URL one is taken to if it’s clicked – the page it links to is in the ortopedicosfuturo.com domain, and is a fake Blackboard login page. And finally, while the message states that the recipient has 2 new messages, it doesn’t give any clear instructions on what needs to be done with them.

Filed Under: PSU Password on a Non-PSU Service Tagged With: bad "from" address, link shown is not the real link, unclear instructions

You have 1 document sent to you via Dropbox shared folder

August 5, 2016 by Paul Carlisle Kletchka

From: “Dropbox” <no-reply@dropboxmail.com>
To: “Recipients” <no-reply@dropbox.com>
Sent: Friday, August 5, 2016 3:50:42 PM
Subject: You have 1 document sent to you via Dropbox shared folder

You have 1 document sent to you via Dropbox shared folder

Log in with your Access ID ***@psu.edu to view shared document.

View Folder <– Link leads to a fake Dropbox log-in page hosted in the boxjewelry.ru domain

NOTE: You are accessing a highly secured shared documents.

Enjoy,
– The Dropbox Team

Dropbox keeps your files safe, synced, and easy to share. To view the document, open folder and sign in with your email to continue to Dropbox.
© 2016 Dropbox

Phish from August 5, 2016 at 3:50 p.m.

This phish is an almost identical repeat of a phish with the same subject from last week.  The signs that it’s a phish are pretty much the same:

  • The generic “Recipients” in the To field
  • The lack of any mention of a specific person’s name in the greeting or information about the sharing properties of the supposed file
  • Penn State has no official affiliation with Dropbox, so you would never use your Access Account to log in to their service (Penn State uses Box, instead)
  • The address linked in the message is not a Dropbox URL, it is in the boxjewelry.ru domain and leads to a fake Dropbox login page

Filed Under: PSU Password on a Non-PSU Service

Important message

August 2, 2016 by Paul Carlisle Kletchka

This phish provides several clues revealing it as a scam message:

  • The “From” address is not actually a Penn State address
  • The “To” address is the same as the “From” address, meaning that recipients were on a Bcc list
  • The greeting is a generic “Dear User”
  • The link appears to be a Penn State link when you look at it, but it actually goes to an address in the joshuafitzgerald.com domain, which has nothing to do with Penn State

Phish from August 2, 2016 at 4:22 p.m.

From: “psu.edu” <xxxxxx@ccri.edu>
Date: Tuesday, August 2, 2016 at 4:22 PM
To: Recipients <xxxxxx@ccri.edu>
Subject: Important message

Dear User,

You have received a new message from Pennsylvania State University Admin System sent to you via Blackboard Learning System.

http://www.psu.edu/blackboard//messagecenter%0118157 <– Links to a fake Blackboard login page in the joshuafitzgerald.com domain

Greetings,

Pennsylvania State University

Filed Under: PSU Message and Generic Site Tagged With: bad "from" address, bad "to" address, bad link address, generic greeting, link shown is not the real link, no personalization

Recently Reported Phishes

  • College Employment Job scam July 3, 2024
  • “MAILBOX VALIDATION” July 23, 2018
  • “New Message For You!” July 19, 2018
  • “Service Require Important Update Due To Insufficient Bandwidth” July 18, 2018
  • “Payment Received!” July 16, 2018
  • “Account-Update” July 16, 2018
  • “A notice from Microsoft(R) Network” July 11, 2018
  • “>>>New messages are on-hold!” July 10, 2018
  • “payment received today.” July 6, 2018
  • “Psu Account User” July 3, 2018

Search for a phishing message…

All Reported Phishes – By Month

  • July 2024
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016

Subscribe to our Phishing feed

  • RSS - Posts
This website is maintained by the Office of Information Security (OIS).
 Visit the Pennsylvania State University Home Page
Copyright 2025 © The Pennsylvania State University Privacy Non-Discrimination Equal Opportunity Accessibility Legal