Friday, November 6, 2009

now you've got yourself to blame

i open my school email this morning and am greeted by this gem of an email:

Greetings,

We are sending you this notice because you may have recently received a
malicious email that appeared to have come from: edillard@gmu.edu
...
In addition the email would have requested that you provide your GMU
email password in order to keep your account open.

Be aware this is a malicious phishing attack. Please do not respond. If
you have responded please contact the ITU Support Center at 703-993-8870
or via email at support@gmu.edu.

No legitimate business or organization will ever ask you to provide your
user name and password via email.


so of course i go look into my trash to see if i had gotten and deleted the message since i dont remember reading it. and i did! here's what it said:

Dear mail.gmu.edu,

We would like to inform you that we are currently carrying out
scheduled maintenance and upgrade of our mail.gmu.edu. mail service
and as a result of this our webmail.gmu.edu client has been changed and your
original password will reset. We are sorry for any inconvenience caused.

To maintain your gmu.edu account, you must reply to this email,
immediately and enter your current password here (..........)Failure to
do this within 48 hours will immediately render your mail.gmu.edu
account deactivated from our database. Thank you for using the
mail.gmu.edu account!

"MAIL.gmu.edu ACCOUNT SUPPORT TEAM".
�MAIL.gmu.edu ACCOUNT ACCOUNT ABN 31 088 377 860 All Rights
Reserved.E-Mail Account Maintenance


from the first line it's way beyond obvious that it's a fake. dear mail.gmu.edu?? really?? and people fell for that?? good phishers always insert the person's name.

so i'm sorry but anyone who fell for this and sent in their password doesnt deserve to have an email. it should be taken away from them immediately because their idiocy levels are too high for them to function normally. they are a menace to the cyber society. in fact, they should be kicked out of the university. because, really, if you're in college right now (it doesnt matter what major) you should know better.

***UPDATE***:

okay mason needs to up their email filters or something. two phishing emails in three days is ridiculous. i got this one today, which is just as bad as the other one. i mean it asks for your date of birth and country/territory. why the hell would that be needed to update a an email?? and watch people fall for this.

Update Your GMU.EDU Email Now.

Dear GMU.EDU Email Owner,This message is from OSU.EDU messaging center to all OSU.EDU Email owners. We are currently upgrading our data base and e-mail

center. We are deleting all unused OSU.EDU email to create more space for new one.To prevent your account from closing you will have to update it below so

that we will know that it's a present used account.

However OSU.EDU has been receiving complaints from our customers for unauthorised use of the GMU.EDU Email. As a result we are making an extra
security check on all of our Customers mailbox in order to protect their information from theft and fraud.

Warning!!! Email owner that refuses to update his or her Email,within two days of receiving this warning will lose his
or her Email permanently.

Contact the GMU Upgrading Center:upgradeedu@gmail.com

Requested Information

OSU Internet username : ...............
Password : ................
Date of Birth : ................
Country or Territory : ..........

Thanks for your co-operation.

Copyright @2009 GMU.EDU . All rights reserved.


Lesson learned: people are stupid, and if any email ever asks for your password for anything then it's a phishing email. real organizations will never do that.

*Fall For Anything - The Script

4 comments:

  1. i got that email today...from afletch6@gmu.edu

    i can't believe someone wud fall for that...

    ReplyDelete
  2. I got one of these emails. so i looked up the guy who sent it to me on facebook. turned out to be some asian kid.

    ReplyDelete
  3. Anonymous... lol thats random. i always thought they'd put fake names...

    ReplyDelete