Don’t Be Fooled! Know How To Spot a Spoofed Email

Submitted by abshaver on

Cybercriminals are always finding new ways to steal people’s information. Recently, we have seen phishing attempts targeting Carilion employees with emails designed to look like official emails from Microsoft programs such as OneDrive or Sharepoint.

“Spoofing” emails are designed to look like emails from legitimate businesses; their intent is to take over the user’s account. Once an employee’s account is compromised, cybercriminals can use it to upload malicious files and steal information (including patient information or other employees’ credentials).

Here are a couple of recent phishing attempts sent to Carilion email addresses (employee names and email addresses have been removed or covered up).

OneDrive spoofed email example

Account lock phishing email

Here are some tips to help you spot a phish:

  • Check the sender address; is it from someone you would expect to send an email?
  • Look for the yellow banner at the top of the email. All external emails will have this banner, so if the message claims to be from Carilion Clinic but has a yellow banner, you can bet this is a phish.
    yellow "external email" banner
  • Look for misspellings and odd wording; while phishing emails can be savvy, they often include misspellings and grammatically incorrect sentences.
  • Phishing emails will try to cause alarm in the receiver; anything marked “urgent” or “act now” should be read over carefully.
  • If you have any doubts about an email, go with your instinct and don’t click on any attachments or links.

If you receive a phishing email (or if you aren’t sure whether an email is legitimate), report it to TSG by using the “Report Phish” button in Outlook.

Report Phish button

Questions?

Visit the TSG hub for more information about phishing and how to spot a suspicious email.

 

Publish date / time
News Type
Users that Liked
5005
3635
Views
0
Thumbnail Image
drawing of a fish hook grabbing someone's password
Unlisted
Off
Banner Image
drawing of a fish hook grabbing someone's password
Designated Comment Contact
emjefferson
Key Points HTML

Cybercriminals often disguise their phishing emails to look like legitimate emails.

If you are not sure whether an email is legitimate, go with your instinct — don't click any links or open any attachments.

If you receive a suspicious email, click the Report Phish button in Outlook to report it.