<?xml version="1.0"?>
<News hasArchived="false" page="15" pageCount="29" pageSize="10" timestamp="Mon, 27 Apr 2026 05:34:58 -0400" url="https://beta.my.umbc.edu/groups/itsecurity/posts.xml?mode=activity&amp;page=15">
<NewsItem contentIssues="false" id="98456" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98456">
<Title>Personal Assistant Job Scam</Title>
<Body>
<![CDATA[
    <div class="html-content"><p><span>The Division of Information Technology (DoIT) has been notified that a scammer is sending out phishing emails claiming to offer an interim personal assistant job available. The offer is a fake.  Below is an example of this scam.</span></p><br><div><table><colgroup></colgroup><tbody><tr><td><p><span>From: </span><span>DJ2205831</span><span> &lt;</span><span><a href="mailto:DJ2205831@pusdk12.org">DJ2205831@pusdk12.org</a></span><span>&gt;</span></p><p><span>Date: Tue, Jan 12, 2021 </span></p><p><span>Subject: University of maryland, baltimore county apply for spring winter p/t jobs work from school/home offer for students 2021</span></p><p><span>To: </span><span>&lt;@umbc.edu&gt;</span></p><p> </p><p><span>I am Annette Bonner, my specializations are foot and ankle, athletic injuries, shoulder and elbow, trauma and</span></p><p><span>fractures, sports medicine, and arthroscopic surgery. Also interested in procedures of replacing shoulders and knees.</span></p><p> </p><p><span>             </span></p><p><span>This message was sent to your email because you have an opportunity from the University Office for Students with</span></p><p><span>Disabilities to work with me to help and assist students with disabilities frustrated with ignorance and lack of services</span></p><p><span>but as my interim personal assistant. I can assure you this employment is very simple, all you need to do are purchase</span></p><p><span>some items when needed, mailing of letters, and making payments at Walmart and this employment won't take much of</span></p><p><span>your time at least two hours daily and three times in a week for ($450).  </span></p><p> </p><p><span>         </span></p><p><span>I am unable to meet up with you for an interview since I am away currently helping the disabled students in</span></p><p><span>Australia, for all the purchases and tasks to get done on my behalf while I am still away, you will be paid in advance.</span></p><p><span>Upon my arrival we will discuss the possibility of making this a long-term employment that if you do really impress me</span></p><p><span>with your services while I am away. My arrival is scheduled for the end of January 2021.</span></p><p> </p><p> </p><p><span>To Apply : Please forward all applications including Full name, Address, Alternate email (different from school</span></p><p><span>email) and mobile number Attached Resume( Its okay if you do not have resume to attach). Please its highly important</span></p><p><span>that you reply and send above information to my personal email address(</span><span><a href="mailto:boseannette85@gmail.com">boseannette85@gmail.com</a></span><span>) so i can respond</span></p><p><span>back to you ASAP.</span></p><p> </p><p> </p><p><span>Best Regards</span></p><p> </p><p><span>Professor Annette Bonner</span></p></td></tr></tbody></table></div><br><p><span>In the example above it can be seen that the email is sent from </span><span>&lt;</span><a href="mailto:DJ2205831@pusdk12.org" rel="nofollow external" class="bo"><span>DJ2205831@pusdk12.org</span></a><span>&gt; and has the subject “University of maryland, baltimore county apply for spring winter p/t jobs work from school/home offer for students 2021”. The phishing email itself is claiming to offer students a job as the scammer’s interim personal assistant. The scammer is asking that applicants respond by emailing their personal information. </span><span> If you have received this email please do not respond.</span></p><br><p><span>Please note that in the phishing email above the scammer states that they can not give an interview.  This is a red flag as most jobs would want some sort of interview or meeting process or at least a telephone call  before hiring anyone. Another red flag is that the email uses words like “high important that you reply,” this gives the user a sense of urgency which can be a sign of phishing and job scam emails.</span></p><br><p><span>Of course, the terrible grammar and punctuation are not what you would expect from a professor of medicine, either.  It is also odd that the message asks the applicant to respond to <u><a href="mailto:boseannette85@gmail.com">boseannette85@gmail.com</a></u> when the message itself came from a different address, <u><a href="mailto:DJ2205831@pusdk12.org">DJ2205831@pusdk12.org</a></u>.</span></p><p><br></p><p>Always be alert for inconsistencies, <em>especially </em>when contacted unexpectedly, <em>especially </em>when contacted by strangers, and <strong><em>most </em></strong><em>especially </em>when money is involved.<br></p><br><p><span>What to do now?</span></p><br><p><span>If you do receive this or a similar scam, please DO NOT respond any further or click on any URLs. If you have provided any banking or financial information, please notify your bank or financial institution immediately. If you have been sent a check, you should not attempt to cash or deposit it. If you have deposited a check already, please contact your bank and tell them that it may be part of a scam.</span></p><br><p><span>Whether or not you responded to the scam or not, please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>. We will also keep track of any other information you submit about the scammers, such as their phone numbers. If you were sent a check or other materials, please send pictures of it and the envelope they came in.</span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a><span> </span></p><br><p><span>To read more articles published by DoIT Security please visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>.  </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a><span> </span></p></div>
]]>
</Body>
<Summary>The Division of Information Technology (DoIT) has been notified that a scammer is sending out phishing emails claiming to offer an interim personal assistant job available. The offer is a fake. ...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/98456/guest@my.umbc.edu/f76b1dab539b62210c3ef9539d02ad93/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Thu, 14 Jan 2021 01:45:52 -0500</PostedAt>
</NewsItem>

<NewsItem contentIssues="true" id="98409" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98409">
<Title>Password Phishing Scam</Title>
<Tagline>Another fake link in an email to steal your password</Tagline>
<Body>
<![CDATA[
    <div class="html-content">This morning we have received reports of a phishing scam targeting members of the UMBC community.  This scam appears to come from the Help Desk, and states that a request was made to deactivate the user's account.  It includes a link to a webpage with a form to steal user passwords.  <strong><u>Do not click this link.</u></strong><div><div><br></div><div>
    <pre>From:  <a href="mailto:HelpDesk@umbc.edu">HelpDesk@umbc.edu</a>&#x000A;    Date: Tue, Jan 12, 2021 at 3:47 AM&#x000A;    Subject:  A REQUEST TO DE-ACTIVATE <a href="mailto:user1@umbc.edu">user1@umbc.edu</a> !&#x000A;    </pre></div><div><img src="https://my3.my.umbc.edu/groups/itsecurity/posts/98409/attachments/38366" style="max-width: 100%; height: auto;"></div><div><br></div><div><img src="https://my3.my.umbc.edu/groups/itsecurity/posts/98409/attachments/38368" style="max-width: 100%; height: auto;"></div><div><br></div><div><p><span>Always check the URL before entering credentials online. Notice that this site is not in the umbc.edu domain, despite claiming to be. In addition, you can compare it to the real login page by navigating to myUMBC without using a link to see that it does not match.</span></p><p><span>As of this writing, several people have clicked this link. If you have entered your UMBC password after clicking the link in this phishing email, change your password to something substantively different as soon as possible as your account has been compromised. Instructions for doing so can be found here:  </span><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867939" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867939</span></a><span>.</span></p><p><span>If you do receive any email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>.</span></p><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a></p></div></div></div>
]]>
</Body>
<Summary>This morning we have received reports of a phishing scam targeting members of the UMBC community.  This scam appears to come from the Help Desk, and states that a request was made to deactivate...</Summary>
<Website>https://itsecurity.umbc.edu</Website>
<AttachmentKind>Image</AttachmentKind>
<AttachmentUrl>https://assets4-beta.my.umbc.edu/system/shared/attachments/e86066c501c74cd94866d2a99d514567/69ef2dc2/news/000/098/409/d9ee5dc208cd7ce588d0ac3b020bdaad/email.PNG?1610465782</AttachmentUrl>
<Attachments>
<Attachment kind="Image" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98409/attachments/38366"></Attachment>
<Attachment kind="Image" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98409/attachments/38368"></Attachment>
</Attachments>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/98409/guest@my.umbc.edu/c6d84dae62410c01f5e6d24f36adc339/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<ThumbnailUrl size="xxlarge">https://assets2-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/xxlarge.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="xlarge">https://assets2-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/xlarge.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="large">https://assets4-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/large.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="medium">https://assets3-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/medium.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="small">https://assets2-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/small.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="xsmall">https://assets1-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/xsmall.jpg?1610469744</ThumbnailUrl>
<ThumbnailUrl size="xxsmall">https://assets4-beta.my.umbc.edu/system/shared/thumbnails/news/000/098/409/0c46f2bf74e751abbae0b298f948c4e4/xxsmall.jpg?1610469744</ThumbnailUrl>
<PawCount>5</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Tue, 12 Jan 2021 11:45:56 -0500</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="98137" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98137">
<Title>FBI and DHHS Warn Public About COVID-19 Scams</Title>
<Tagline>This December is a Perfect Season For Scammers</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><span>December is a month of holidays, travel, and family gatherings.  Most years, December creates extra stress but makes up for it with special occasions enjoyed with family and friends.  This year, there will be less enjoyment of those special occasions and, for most of us, a lot more stress as we remain locked down awaiting the widespread dissemination of the COVID-19 vaccines.  The lockdown has many of us feeling disoriented, isolated, angry, or afraid.  This is both perfectly</span><span> normal and j</span><span>ust the state of mind that scammers like to see.</span><div><br></div><p><span>Expect to see and/or hear about fake vaccine scams in the coming weeks.  The scams will differ in intent.  Some will encourage you to use your credit card or bank account to send the scammers money in order to assure vaccination quickly.  Others may simply ask you to fill out an online form with lots of personal information.  Some may even offer you a work-from-home job calling people about vaccination.  Whatever the scam is, the COVID-19 vaccine will be the bait.</span></p><br><br><p><span>From the FBI</span></p><p><span>Special Agent in Charge Timothy Thibault recently <a href="https://abcnews.go.com/US/fbi-warns-covid-19-vaccine-scams/story?id=74631650" rel="nofollow external" class="bo">told </a>ABC News:</span></p><br><p><span>"What we would say to the public is to be leery of and be on guard for scams related to telemarketing, malicious websites or emails where people are taking advantage of the initial supply-and-demand problem"</span></p><br><br><p><span>From the Department of Health and Human Services (DHHS)</span></p><p><span>The DHHS Office of Inspector General issued an <a href="https://oig.hhs.gov/coronavirus/fraud-alert-covid19.asp" rel="nofollow external" class="bo">alert </a>earlier this month warning:</span></p><br><ul><li><p><span>Be vigilant and protect yourself from potential fraud concerning COVID-19 vaccines. You will not be asked for money to enhance your ranking for vaccine eligibility. Government and State officials will not call you to obtain personal information in order to receive the vaccine, and you will not be solicited door to door to receive the vaccine.</span></p></li><li><p><span>Beneficiaries should be cautious of unsolicited requests for their personal, medical, and financial information. Medicare will not call beneficiaries to offer COVID-19 related products, services, or benefit review.</span></p></li><li><p><span>Do not respond to, or open hyperlinks in, text messages about COVID-19 from unknown individuals.</span></p></li><li><p><span>Be aware of scammers pretending to be COVID-19 contact tracers. Legitimate contact tracers will never ask for your Medicare number, financial information, or attempt to set up a COVID-19 test for you and collect payment information for the test.</span></p></li><li><p><span>If you suspect COVID-19 health care fraud,</span><a href="https://oig.hhs.gov/fraud/report-fraud/" rel="nofollow external" class="bo"><span>report it immediately online</span></a><span> or call 800-HHS-TIPS (800-447-8477).</span></p></li></ul><div><br></div><div><br></div><p><span>Spotting Scams</span></p><p><span><br></span></p><p><span>There are two important components to any scam.  First, the scammer must offer to provide you with something you very much want, or to prevent something you very much </span><span>don’t</span><span> want.  Second, the scammer will create a sense of urgency to discourage you from doing any background check or even from thinking too hard about the offer.</span></p><br><p><span>If you receive email, phone calls, text messages, or anything else that appeals to your hopes and fears and tries to create a sense of urgency, be suspicious.  The more urgent it seems, the more you need to check out the source.</span></p><br><p><span>For more information about spotting potential COVID-19 scams, please visit:</span></p><br><ul><li><p><a href="https://scamspotter.org/" rel="nofollow external" class="bo"><span>https://scamspotter.org</span></a></p></li><li><p><a href="https://www.washingtonpost.com/business/2020/12/14/covid-19-vaccine-scams/" rel="nofollow external" class="bo"><span>https://www.washingtonpost.com/business/2020/12/14/covid-19-vaccine-scams</span></a></p></li><li><p><a href="https://my3.my.umbc.edu/groups/itsecurity/posts/98136" rel="nofollow external" class="bo"><span>https://my3.my.umbc.edu/groups/itsecurity/posts/98136</span></a></p></li></ul><br><p><span>If you do receive any email that you suspect is a scam, please do not even click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. If you are a member of the UMBC community, please forward the message (with the email headers - see </span><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>here </span></a><span>for instructions)) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>. </span></p><br><br><p><span>References and Links to More Information</span></p><br><ul><li><p><a href="https://abcnews.go.com/US/fbi-warns-covid-19-vaccine-scams/story?id=74631650" rel="nofollow external" class="bo"><span>https://abcnews.go.com/US/fbi-warns-covid-19-vaccine-scams/story?id=74631650</span></a></p></li><li><p><a href="https://oig.hhs.gov/coronavirus/fraud-alert-covid19.asp" rel="nofollow external" class="bo"><span>https://oig.hhs.gov/coronavirus/fraud-alert-covid19.asp</span></a></p></li><li><p><a href="https://www.washingtonpost.com/business/2020/12/14/covid-19-vaccine-scams/" rel="nofollow external" class="bo"><span>https://www.washingtonpost.com/business/2020/12/14/covid-19-vaccine-scams/</span></a></p></li><li><p><a href="https://www.aarp.org/money/scams-fraud/info-2020/coronavirus-vaccine-scams.html" rel="nofollow external" class="bo"><span>https://www.aarp.org/money/scams-fraud/info-2020/coronavirus-vaccine-scams.html</span></a></p></li><li><p><a href="https://www.fda.gov/consumers/consumer-updates/beware-fraudulent-coronavirus-tests-vaccines-and-treatments" rel="nofollow external" class="bo"><span>https://www.fda.gov/consumers/consumer-updates/beware-fraudulent-coronavirus-tests-vaccines-and-treatments</span></a></p></li></ul><br><br></div>
]]>
</Body>
<Summary>December is a month of holidays, travel, and family gatherings.  Most years, December creates extra stress but makes up for it with special occasions enjoyed with family and friends.  This year,...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/98137/guest@my.umbc.edu/3673051294041d9f3b8108c6eb36804c/api/pixel</TrackingUrl>
<Tag>covid19</Tag>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Wed, 16 Dec 2020 17:40:18 -0500</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="98136" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/98136">
<Title>Tips on Identifying Phishing Scams</Title>
<Tagline>Think, Then Slow Down And Think Again</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><p><span>The article linked below lists a few tips on how to identify phishing scams in your daily life or while you are working. Here is a short list of some clues to help identify phishing emails.</span></p><br><ul><li><p><span>The email address does not match business name or location. </span><span>With many phishing emails if you look closely at the FROM address, you might notice misspelling  or even something that doesn’t match the organization at all. One type that has been seen at UMBC are scammers having an email that ends with &lt;</span><a href="mailto:.umbc@gmail.com" rel="nofollow external" class="bo"><span>.umbc@gmail.com</span></a><span>&gt; to try and trick users into thinking it is from a UMBC source.</span></p></li><li><p><span>A sense of urgency.</span><span> Many phishing emails will have a sense of urgency that are created to distract the user from the emails true intentions. The idea is that the victim is too preoccupied with getting the action completed to see that it is a false request.</span></p></li><li><p><span>Uncommon request from someone within the organization.</span><span> Is this email coming from someone you do not normally work with? Would they normally be asking you to help complete this task or project? </span></p></li><li><p><span>Poor grammar and spelling. </span><span>Many times the true sign of a suspicious email are common words being misspelled. There could also be capitalizations in almost random spots of a sentence and the spacing between words might be off.</span></p></li></ul><br><p><span>Phishing scams are not the only tactics that are used by malicious actors. Many are impersonating or creating fake charities and using social media to further expand their campaign. Twitter has been seeing many of the “send me $1 and I will send you $2” scams as well as an increase in scams promoting bitcoins.</span></p><br><p><span>With charities, malicious actors are creating seemingly wholesome and thorough charity websites or social media profiles to target those who want to help. These scams often come as telemarketers or prompted phone calls. If you would like to give to an organization please do your research before giving any personal or financial information.</span></p><br><p><span>If you do receive any email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>. </span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a><span> </span></p><br><p><span>For more information, please check out: </span></p><p><a href="https://securityboulevard.com/2020/08/identifying-covid-19-phishing-scams/" rel="nofollow external" class="bo"><span>https://securityboulevard.com/2020/08/identifying-covid-19-phishing-scams/</span></a></p><br><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>.  </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a><span> </span></p></div>
]]>
</Body>
<Summary>The article linked below lists a few tips on how to identify phishing scams in your daily life or while you are working. Here is a short list of some clues to help identify phishing emails....</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/98136/guest@my.umbc.edu/1923923df93a76560685f7dc6e4dc172/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Wed, 16 Dec 2020 17:30:33 -0500</PostedAt>
</NewsItem>

<NewsItem contentIssues="true" id="97700" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/97700">
<Title>Job Scams Continue To Target UMBC Community</Title>
<Tagline>Scammers Don&#8217;t Take Time Off For The Holidays</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><span>UMBC’s Division of Information Technology (DoIT) is seeing an increase in the number of job scams targeting the UMBC community.  It is not uncommon for scammers to take advantage of people during busy or stressful times, and this holiday season is certainly no exception.   People under COVID-19 restrictions may feel isolated and disoriented.  The economic impact of the restrictions means that many people are short of money.  All of these factors bring out those who will exploit the situation in order to take advantage of others.   </span><br><br><p><span><strong>How It Works</strong></span></p><br><p><span>Not all job scams are identical, but those we have seen follow the general pattern described here.</span></p><br><p><span>You may see scams arrive as text messages, email, or in almost any other form possible.  The messages are all similar.  You are told that the sender has some association with your school and that you have been selected to apply for a work-from-home position.  You are asked to contact the sender and/or go to a website to provide personal information, including name, address, phone number, email address, and possibly Social Security Number.  Some scammers go to considerable effort to appear legitimate.  They may have set up a website.  They may even use the names of real people from real companies. One very through scam earlier this year took names and photos from the website of a real company and used it to set up their own website.</span></p><br><p><span>Once you have accepted the position, you will be provided with either a check or a picture of a check to print out and be directed to deposit it into your checking account.  At the same time, for whatever reason, you will be told to transfer some of your own money (check, wire transfer, etc.) to someone else.  For instance, if the check you get is for $1000.00, you may be told to deposit it and </span><span>immediately</span><span> send $700.00 to someone else, keeping the remaining $300.00 as your payment for the work.  The check for $1000.00 turns out to be a fake and is rejected by your bank.  You have just </span><span>lost</span><span>$700.00.  The scammer you have been working for will stop responding.  Any contact information you have will no longer be valid.  </span></p><br><p><span></span></p><br><p><span><strong>Some Examples</strong></span></p><div><br></div><div><br></div><div><span><em>Text message</em></span></div><br><p><span><img src="https://lh6.googleusercontent.com/sxqz_xrOdJRVy3viZmyC7JKYwao99bPnhAcArB4BxWByy7bnmgNBrbsi6ltN-fbffZQbQEfBuHUDTzul0WhMvfazVHg0pxYhWSrZz1zoKsGQkepJmS-YRTVdeeNXNr5oSClpbjLs" width="317" height="574" style="max-width: 100%; height: auto;"></span></p><br><br><br><p><span><em>E-mail message</em></span></p><div><table><colgroup></colgroup><tbody><tr><td><p><span>From: </span><span>Kaitlyn pederio</span><span> &lt;<a href="mailto:kaitlynpe541@gmail.com">kaitlynpe541@gmail.com</a>&gt;</span></p><p><span>Date: Wed, Nov 25, 2020 at 3:02 PM</span></p><p><span>Subject: CORNERSTONE STUDENT PART TIME JOB OFFER</span></p><p><span>To: </span></p><br><p><span>Dear student,</span></p><br><p><span>   We got your contact through your school database and I'm happy to inform you that our reputable company Cornerstone® is currently running a student empowerment program. This program is completely school oriented as it has been designed not to deter you from all school activities which is priority for you and this organisation. This program is to help loyal and hardworking students like you secure a part time job with an attractive weekly salary.</span></p><p><span>TO PROCEED WITH THIS JOB OFFER, KINDLY REPLY TO THIS MAIL WITH YOUR ALTERNATE E-MAIL ADDRESS IN ORDER TO RECEIVE THE FULL JOB DESCRIPTION.</span></p><br><p><span>Best Regards,</span></p><p><span> </span></p><p><span>Kaitlyn pederio, </span></p><p><span>HR Recruit Manager/Consultant</span></p><p><span>Cornerstone®</span></p><p><span>Staffing-Solution,</span></p><br></td></tr></tbody></table></div><br><br><p><strong><span><strong>What to do</strong></span></strong></p><p><span><br></span></p><p><span>If you do receive anything like the offers above, even if you are not sure, , please DO NOT respond any further or click on any URLs. If you have provided any banking or financial information, please notify your bank or financial institution immediately. If you have been sent a check, you should not attempt to cash or deposit it. If you have deposited a check already, please contact your bank and tell them that it may be part of a scam.</span></p><br><p><span>Whether or not you responded to the scam or not, please forward the message (with the email headers - see link below) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>. We will also keep track of any other information you submit about the scammers, such as their phone numbers if you receive a text message from the scammer.</span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a><span> </span></p><br><p><span>To read more articles published by DoIT Security please visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>.  </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a><span> </span></p><br><br><br><br><br><br></div>
]]>
</Body>
<Summary>UMBC’s Division of Information Technology (DoIT) is seeing an increase in the number of job scams targeting the UMBC community.  It is not uncommon for scammers to take advantage of people during...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/97700/guest@my.umbc.edu/6b2a6f372ef1f8f138947428debfa105/api/pixel</TrackingUrl>
<Tag>covid19</Tag>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Wed, 25 Nov 2020 19:12:53 -0500</PostedAt>
<EditAt>Wed, 25 Nov 2020 19:42:36 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="96410" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/96410">
<Title>Job Scam &#8220;WorkStudy!&#8221; From a Compromised UMBC Account</Title>
<Body>
<![CDATA[
    <div class="html-content"><p><span>Recently DoIT was notified of a job scam email campaign from a compromised UMBC email account. The email has the subject line “WorkStudy!” and is presenting a fake job offer to the user. Below is an example of the job scam email, with the name and email of the From and To removed for privacy reasons.</span></p><br><div><table><colgroup></colgroup><tbody><tr><td><p><span>From: </span><span>COMPROMISED ACCOUNT</span><span> &lt;</span><span>@umbc.edu</span><span>&gt;</span></p><p><span>Date: Tue, Sep 22, 2020 at 4:53 PM</span></p><p><span>Subject: WorkStudy!</span></p><p><span>To: &lt;@umbc.edu&gt;</span></p><br><br><p><span>Good Day!</span></p><p><span>I hope you are well. I would like to share with you this job opportunity,you could earn between $100- $240 weekly. This opportunity is only part time and is not expected to clash with your current school/study schedule.Kindly send in an instant reply if you are in search of a job so you can receive further information.</span></p></td></tr></tbody></table></div><br><p><span>Please note that the email is coming from a compromised UMBC account but the reply-to in the headers is set to &lt;</span><a href="mailto:careerjobsdepartment@outlook.com" rel="nofollow external" class="bo"><span>careerjobsdepartment@outlook.com</span></a><span>&gt;. This means that if the user responds to the email they would not be responding to the UMBC email but instead the scammer directly at &lt;</span><a href="mailto:careerjobsdepartment@outlook.com" rel="nofollow external" class="bo"><span>careerjobsdepartment@outlook.com</span></a><span>&gt;.</span><span><br></span><span><br></span><span>If you do receive this or a similar email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>.</span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a></p><br><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>. </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a></p></div>
]]>
</Body>
<Summary>Recently DoIT was notified of a job scam email campaign from a compromised UMBC email account. The email has the subject line “WorkStudy!” and is presenting a fake job offer to the user. Below is...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/96410/guest@my.umbc.edu/ecc46207dfbcd7af153cb0c9430886a3/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Tue, 06 Oct 2020 16:20:50 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="96409" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/96409">
<Title>Scam Emails Trying to Impersonate a UMBC Member</Title>
<Tagline>Look Closlely At The Headers Before You Respond</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><p><span>Below is an example of a scam email that has recently been reported to DoIT. The email below the scammer tries to impersonate a member of the UMBC by setting the From email name to that of a UMBC email user. The name has been removed for privacy reasons. </span></p><br><div><table><colgroup></colgroup><tbody><tr><td><p><span>From: </span><span>FORGED NAME </span><span>&lt;</span><span><a href="mailto:hya270926@gmail.com">hya270926@gmail.com</a></span><span>&gt;</span></p><p><span>Date: Tue, Sep 15, 2020 </span></p><p><span>Subject: UMBC Student Government Association</span></p><p><span>To: &lt;</span><span>@umbc.edu</span><span>&gt;</span></p><br><br><p><span>Hello &lt;Users Name&gt;, </span></p><br><p><span>                How are you doing today, I hope this finds you well? Are you currently free? Please I need you to handle a request on my behalf, If yes, email me at the earliest opportunity. </span></p><br><p><span>Regards</span></p><p><span>FORGED NAME</span></p></td></tr></tbody></table></div><br><p><span>This recent phishing attempt has the scammer trying to impersonate a member of the UMBC. These emails are a bit more personalized with the scammer saying “Hello &lt;Users Name&gt;” as well as having the impersonated name at the bottom of the email in the email’s signature.</span></p><br><p><span>This email does show some red flags of being a phishing email. First, the email itself is coming from a Gmail account and not a UMBC email account. Second, the email itself has a sense of urgency, urging the user to respond at the “earliest opportunity.”</span></p><br><p><span>If you do receive this or a similar email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>.</span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a></p><br><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>. </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a></p><br><br></div>
]]>
</Body>
<Summary>Below is an example of a scam email that has recently been reported to DoIT. The email below the scammer tries to impersonate a member of the UMBC by setting the From email name to that of a UMBC...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/96409/guest@my.umbc.edu/0966fd5212c7160156c2780b2412d39e/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Tue, 06 Oct 2020 16:18:42 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="96407" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/96407">
<Title>Job Scam &#8220;_Available&#8221; From a Compromised UMBC Account</Title>
<Tagline>Another Job Scam</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><p><span>DoIT has recently been notified of a job scam coming from a compromised UMBC email account, below is an example of that message that was being sent. The subject line of the job scam email is “_Available.” The name and email address of the From and To users were removed for privacy reasons.</span></p><br><div><table><colgroup></colgroup><tbody><tr><td><p><span>From: COMPROMISED ACCOUNT &lt;</span><span>@umbc.edu</span><span>&gt;</span></p><p><span>Date: Mon, 14 Sep 2020 </span></p><p><span>Subject: _Available</span></p><p><span>To: &lt;@umbc.edu&gt;</span></p><br><p><span>For an opportunity to work remotely as an assistant write to sign up.</span></p><br><p><span>Regards,</span></p><p><span>COMPROMISED ACCOUNT</span></p></td></tr></tbody></table></div><br><p><span>Please note that the email above is coming from a UMBC email account, but within the email headers it shows that the reply-to is set to a &lt;<a href="mailto:charlenabolinlyco21@gmail.com">charlenabolinlyco21@gmail.com</a>&gt;. This means that if the user tries to respond to this email they would not be emailing the compromised UMBC account but instead the scammer directly at &lt;<a href="mailto:charlenabolinlyco21@gmail.com">charlenabolinlyco21@gmail.com</a>&gt;.</span><span><br></span><span><br></span><span>If you do receive this or a similar email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to </span><a href="mailto:security@umbc.edu" rel="nofollow external" class="bo"><span>security@umbc.edu</span></a><span>.</span></p><br><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a></p><br><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>. </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a></p></div>
]]>
</Body>
<Summary>DoIT has recently been notified of a job scam coming from a compromised UMBC email account, below is an example of that message that was being sent. The subject line of the job scam email is...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/96407/guest@my.umbc.edu/7d6693c1b75ad548e06d07ef5235a7b8/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Tue, 06 Oct 2020 16:13:05 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="96406" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/96406">
<Title>Tracking Code Scam</Title>
<Tagline>Purchasing Non-Existent Goods</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><h3><span>Tracking Code Scam</span></h3><br><p><span>The Better Business Bureau warns of a scam where malicious actors aim to deceive online shoppers into paying for goods that do not actually exist. This is done by the scammers creating fake websites that are selling products with great deals, usually selling brand named goods at a significant discount.</span></p><br><p><span>If the user decides to take a chance and make the purchase, the site is said to instruct the user to pay through PayPal. After checkout the user will receive a tracking number from UPS, FedEx, or another shipping service. After awhile if the user checks the package is said to be delivered but to the wrong address.</span></p><br><p><span>If the user tries to contact the website they will learn that the site is either unresponsive or unhelpful. Some cases, the site does not even provide contact information and in others they just do not respond to any emails or calls.</span></p><br><p><span>Some of the victims of this scam reported filing a claim with PayPal for their money back but because the scammer technically shipped the package and the tracking number marked it as delivered, PayPal was rejecting their claims.</span></p><br><p><span>The articles linked below gives some tips on spotting Package Delivery Scams and other online shopping related scams:</span></p><ul><li><p><span>Before paying, know your rights and responsibilities. In any type of scam, scammers might try to take advantage of what consumers do not know when it comes to processing payment. Do not make a purchase from any seller that seems suspicious and do not assume that you’ll be protected no matter what.</span></p></li><li><p><span>Before buying online, confirm the site has real contact information. Make sure the seller has a working phone number and address on the website, so you can contact them in case of a problem.</span></p></li><li><p><span>If the price seems too good to be true, then it probably is. Be wary if the item is selling for significantly lower than what you have seen elsewhere.</span></p></li><li><p><span>Make sure you know who you are dealing with, they advise you check the spelling and the domain names. As well as to google the website to see if the website has had any complaints.</span></p></li><li><p><span>Scam websites usually have poor grammar and spelling, a lack of information, and capital letters in the middle of sentences.</span></p></li><li><p><span>Make sure the website is using https:// as a trusted website will have a secure domain so that your information is safe. Make sure to also check the address bar for a “not secure” message as that is another red flag.</span></p></li><li><p><span>Check for the website's privacy policy to understand what personal information is being requested. If there isn’t a privacy policy that is a red flag.</span></p></li><li><p><span>Research the business first to make sure it is legitimate before giving them any of your personal and/or financial information.</span></p></li></ul><p><span>For more information, please check out: </span></p><p><a href="https://www.bbb.org/article/scams/21097-scam-alert-tracking-code-trick-costs-online-shoppers" rel="nofollow external" class="bo"><span>https://www.bbb.org/article/scams/21097-scam-alert-tracking-code-trick-costs-online-shoppers</span></a></p><p><a href="https://www.bbb.org/article/news-releases/22474-bbb-warning-be-careful-purchasing-from-unknown-websites-during-covid-19" rel="nofollow external" class="bo"><span>https://www.bbb.org/article/news-releases/22474-bbb-warning-be-careful-purchasing-from-unknown-websites-during-covid-19</span></a></p><p><a href="https://www.bbb.org/article/tips/14040-bbb-tip-smart-shopping-online" rel="nofollow external" class="bo"><span>https://www.bbb.org/article/tips/14040-bbb-tip-smart-shopping-online</span></a></p><br><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>. </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a></p><br><br></div>
]]>
</Body>
<Summary>Tracking Code Scam   The Better Business Bureau warns of a scam where malicious actors aim to deceive online shoppers into paying for goods that do not actually exist. This is done by the scammers...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/96406/guest@my.umbc.edu/b76f6775e67bd39e168f424dcbb98691/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Tue, 06 Oct 2020 16:10:51 -0400</PostedAt>
</NewsItem>

<NewsItem contentIssues="false" id="95702" important="false" status="posted" url="https://beta.my.umbc.edu/groups/itsecurity/posts/95702">
<Title>"Email Configuration Error" Phishing Attack</Title>
<Tagline>Phishing Attack Masquerading As Email Delivery Problem</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><p><span>A phishing attack urging users to download undelivered emails was reported to DoIT Security this week. Here is an example of the malicious message.</span></p><p><span> </span></p><p><span>From: "</span><a href="http://umbc.edu/" rel="nofollow external" class="bo"><span>umbc.edu</span></a><span> System Administrator" &lt;</span><span><a href="mailto:admin@secureserver.net">admin@secureserver.net</a></span><span>&gt;</span></p><p><span>Subject: You have 4 undelivered emails. Download them now</span></p><p><span>Date: 03 Sep 2020 14:40:40 +0800</span></p><p><span> </span></p><p><span>Undelivered Mail Notification</span></p><p><span>Email account: (redacted)@umbc.edu</span></p><p><span>Time of error 9/3/2020 2:40:40 p.m.</span></p><p><span>Due to a recent configuration error, some of your emails have not been properly synchronized with your mailbox. Login below to clear this error and download your mails.</span></p><p><span>Download your emails</span></p><p><span>If you do not retrieve your undelivered emails now, they may be lost forever.</span></p><p><span>umbc.edu Email Server</span></p><p><span> </span></p><p><span>The link to “download” undelivered emails leads to a website which prompts users to enter their UMBC credentials, potentially giving malicious actors access to victims’ UMBC accounts.</span></p><p><span>Notice the warning signs in this email. First, check the sender address, and notice that the supposed </span><span>"</span><a href="http://umbc.edu/" rel="nofollow external" class="bo"><span>umbc.edu</span></a><span> System Administrator" is not using a umbc.edu address. Next, check the time and time zone of the message. The time zone UTC+0800 is used in China and parts of Australia and Russia, for example, but not anywhere that a legitimate email about your UMBC account would likely originate. Finally, be wary of unexpected emails requiring immediate action. Malicious actors try to induce panic to make victims act before thinking about the risks.</span></p><p><span>See a similar email reported at the </span><span>University of North Carolina at Chapel Hill:</span></p><p><a href="https://its.unc.edu/phish-alert/you-have-9-pending-emails-download-them-now/" rel="nofollow external" class="bo"><span>https://its.unc.edu/phish-alert/you-have-9-pending-emails-download-them-now/</span></a></p><p><span> </span></p><p><span>If you do receive this or any other email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Please forward the message (with the email headers) to <a href="mailto:security@umbc.edu">security@umbc.edu</a>.</span></p><p><span> </span></p><p><span>How do I forward full email headers?</span></p><p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo"><span>https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970</span></a></p><p><span> </span></p><p><span>To read more articles published by DOIT visit: </span></p><p><a href="https://itsecurity.umbc.edu/critical/?tag=notice" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/critical/?tag=notice</span></a><span>. </span></p><p><a href="https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19" rel="nofollow external" class="bo"><span>https://itsecurity.umbc.edu/home/covid-19-news/?tag=covid19</span></a></p><br><br></div>
]]>
</Body>
<Summary>A phishing attack urging users to download undelivered emails was reported to DoIT Security this week. Here is an example of the malicious message.     From: "umbc.edu System Administrator"...</Summary>
<TrackingUrl>https://beta.my.umbc.edu/api/v0/pixel/news/95702/guest@my.umbc.edu/68be8a3d5c92fcffa674d8f63d9fc541/api/pixel</TrackingUrl>
<Tag>notice</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://beta.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="original">https://assets4-beta.my.umbc.edu/images/avatars/group/7/original.png?1777162216</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="xlarge">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xlarge.png?1777162216</AvatarUrl>
<AvatarUrl size="large">https://assets4-beta.my.umbc.edu/images/avatars/group/7/large.png?1777162216</AvatarUrl>
<AvatarUrl size="medium">https://assets4-beta.my.umbc.edu/images/avatars/group/7/medium.png?1777162216</AvatarUrl>
<AvatarUrl size="small">https://assets1-beta.my.umbc.edu/images/avatars/group/7/small.png?1777162216</AvatarUrl>
<AvatarUrl size="xsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xsmall.png?1777162216</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets1-beta.my.umbc.edu/images/avatars/group/7/xxsmall.png?1777162216</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>0</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Fri, 11 Sep 2020 11:22:42 -0400</PostedAt>
</NewsItem>

</News>
