Educause Security Discussion mailing list archives

Re: phishing irony


From: Dan Oachs <doachs () GAC EDU>
Date: Wed, 11 Feb 2009 07:57:54 -0600

Is there any chance that someones outbound mailserver added that to the
top of the message as a warning?  Would be an interesting idea but
probably would not stop many users from responding with their password
anyway :)

--Dan


Jesse Thompson wrote:
I found a phish message today with the following at the top of the
message:

========================================================================
PHISHING: Legitimate organizations NEVER ask for your SSN, password,
account number, or other personal data.  Do NOT ever provide such
information to anyone via email.
========================================================================

It was then followed by the usual request to reply to the @live.com
address with account credentials.

I can't figure out if the phishers are being stupid or genius.

Jesse

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


Current thread: