Search Information Security site

 

Information Security Alerts & Warnings

This page lists current warnings regarding suspicious email messages and other cybersecurity hazards at the University of Virginia.

Regarding Suspicious Email Alerts

Messages similar to the suspicious emails listed below may be related to phishing scams, schemes to commit identity theft, or other attempts to compromise users’ machines or personal information.

  • If you receive an email similar to any of the suspicious emails on this page, DO NOT respond—delete it immediately!
  • Do not click any links in the email, and do not “unsubscribe” or acknowledge the email in any way.
  • If you receive an email that appears “phishy” and are unsure if it’s legitimate, and it is not listed below, please report it to us. Forward it to our IT-Abuse team.

Suspicious Items Currently Affecting UVa:

[Posted: Nov 14, 2017 12:30 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: jq23fl @ virginia.services
Date: November 14, 2017 at 8:45:52 AM EST
To: mcp4n @ virginia.edu>

Good morning, Mary

I hope you had a good vacation to Disney World. I look forward to seeing your pictures of the mouse.

I complied the performance review data for all UVA employees. The data did correlate as you suspected.

Please let me know if you have any questions or want me to run a different report.

Link to the file: hxxps://virginia.box.com/n/e46d69abde01f581f79cd4ec029a8469

Thank you,
John

Virginia HR Specialist 

[Posted: Nov 14, 2017 12:30 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: rikki-maria@ clear.net.nz  On Behalf Of @virginia
Sent: Tuesday, November 14, 2017 12:23 PM
To: info @ mail.com

Hello,

There  is a congestion on our database. We are currently de-activating inactive Virginia webmail. Kindly confirm your Virginia webmail is still active with the link below; hxxps://webaccessverification.yolasite.com/

Copyright (c) 2017, University of Virginia. All rights reserved.

[Posted: Nov 10, 2017 10:00 AM]

--------------- Original Message ---------------
From: Bobby Clifton [bobby_clifton[at]mednax.com]
Sent: 11/9/2017 8:09 PM
To: 
Subject: IMPORTANT: VIEW THE DOCUMENT
 
This message was sent securely by Mednax<hxxp://www.mednax.com/>
 
 
Hello,
I've been trying to send you this, I uploaded it using dropbox as I'm having problems with attachments. Document Attached Access it via Dropbox and the file is secured and you will need to login with your email to access it. .
 
 
www.dropbox.com <hxxp://jobradshaw.co.uk/Su/Val/>
 
Dropbox Service!
Regards.
 
 
 
 
This message was secured by Zix<hxxp://www.zixcorp.com>®.
ref:_00D36ouwd._50036MTRYo:ref

[Posted: Nov 9, 2017 9:30 AM]

From: nuria.lorenzo[at]ub.edu <nuria.lorenzo[at]ub.edu>
Sent: Thursday, October 26, 2017 6:25 AM
To: Recipients
Subject: Important information..
 
 
[cid:embedding-0]
 
Your password will expire within 2 days and we discover an unusual ip access unknown (120.612.105.108) on our database computer.
Outlook Web Access automatically cleans itself to ensure that your account is protected against unauthorized access to your mailbox. CLICK HERE<hxxp://beam.to/j-campuse-mail>  to prevent deactivation.
 
System Administrator.
 
 
Aquest correu electrònic i els annexos poden contenir informació confidencial o protegida legalment i està adreçat exclusivament a la persona o entitat destinatària. Si no sou el destinatari final o la persona encarregada de rebre’l, no esteu autoritzat a llegir-lo, retenir-lo, modificar-lo, distribuir-lo, copiar-lo ni a revelar-ne el contingut. Si heu rebut aquest correu electrònic per error, us preguem que n’informeu al remitent i que elimineu del sistema el missatge i el material annex que pugui contenir. Gràcies per la vostra col·laboració.
 
Este correo electrónico y sus anexos pueden contener información confidencial o legalmente protegida y está exclusivamente dirigido a la persona o entidad destinataria. Si usted no es el destinatario final o la persona encargada de recibirlo, no está autorizado a leerlo, retenerlo, modificarlo, distribuirlo, copiarlo ni a revelar su contenido. Si ha recibido este mensaje electrónico por error, le rogamos que informe al remitente y elimine del sistema el mensaje y el material anexo que pueda contener. Gracias por su colaboración.
 
This email message and any documents attached to it may contain confidential or legally protected material and are intended solely for the use of the individual or organization to whom they are addressed. We remind you that if you are not the intended recipient of this email message or the person responsible for processing it, then you are not authorized to read, save, modify, send, copy or disclose any of its contents. If you have received this email message by mistake, we kindly ask you to inform the sender of this and to eliminate both the message and any attachments it carries from your account. Thank you for your collaboration.

[Posted: Nov 9, 2017 9:30 AM]

From: Keyanna Dawson <kdawson[at]kcpublicschools.org>
Sent: Monday, October 23, 2017 4:46 AM
Subject: University of Virginia Office 365 Web Access Central Sign On Authentication Help Desk
 

This is your final warning.Your University of Virginia Office 365 Web Access Email has exceeded its Quota limit Click  Office 365 Online Account Validate to sign in for upgrade and advance mailbox features OR you will be deactivated permanently and you may not be able to send or receive new mail until you re-validate your University of Virginia Office 365 Web Access.

Disclaimer

The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful.

This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing asafer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more Click Here.

 

[Posted: Nov 8, 2017 2:00 PM]

-----Original Message-----
From: rikki-maria[at]clear.net.nz [mailto:rikki-maria[at]clear.net.nz] 
Sent: Wednesday, November 8, 2017 1:46 PM
To: info[at]mail.com
Subject: Web Access
 
Hello, Your @virginia email account has being logged in from an unfamiliar location. Kindly verify your @virginia E-mail account with the link below before you log-in to avoid de-activation.  
 
hxxps://webaccessverification.yolasite.com/

[Posted: Nov 7, 2017 3:45 PM]

--------------------------------
Request Confirmation: 65189W5G64H2
--------------------------------
Date: 11/07/2017
--------------------------------
 
 We hereby inform you that the University of Virginia has queued all email addresses in her database for validation. The reason for this is to sort out all inactive emails from the database and suspend access to them or deactivate them. Therefore, if you know that your email address is still active, please click here and login for your e-mail account to be marked as active. Subsequent information will be passed on to you after successful logon.
 
 Remember, we shall pass this message around a few times and afterwards suspend access to email addresses which are not verified and will terminate this service to quarantine this activity.
 
 
-----------------------------------
Help Desk and Compliance Officer.
Mail Administration | IT Solutions.
 
 
 © 2017 BY THE RECTOR AND VISITORS OF THE UNIVERSITY OF VIRGINIA.
 
 
---
This email has been checked for viruses by Avast antivirus software.

[Posted: Nov 6, 2017 3:45 PM]

From: Microsoft Office 365 [mailto:simzak[at]hughes.net]
Sent: Friday, November 03, 2017 11:12 AM
To: teresa.ochoa[at]erau.edu
Subject: Your Email Account has been suspended
 
 
Your Microsoft Account has been suspended.
 
 
 
 
On Friday, November 3, 2017 12:01 AM GMT, we noticed security concerns on your email. your email have been reported performing illegal activities such as sending spam mails.
 
If this is your account please sign in from your regularly used device to avoid your account from being suspended.
 
Please visit the resolve link to stop this problem.
 
Resolve Now<hxxp://akarsujewellery.com/zoom/index.html>
 
Note: If this process is not completed within 24-48 hours we will be forced to disable your Microsoft account as it may have been used for fraudulent purposes.
 
Sincerely,
The Microsoft Directory Team
 
 
 
 
 
Microsoft Corporation | One Microsoft Way Redmond, WA 98052-6399
 
This message was sent from an unmonitored email address. Please do not reply to this message.
 
Privacy <http://akarsujewellery.com/zoom/index.html> | Legal <hxxp://akarsujewellery.com/zoom/index.html>
 
Disclaimer
 
The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful.
 
This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing a safer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more visit the Mimecast website.

[Posted: Nov 6, 2017 3:30 PM]

-----Original Message-----
From: EDU USER [mailto:mounchick5[at]q.com] 
Sent: Monday, November 6, 2017 2:53 PM
To: amtaul001[at]hotmail.com
Subject: Re:-----
 
Dear Edu  User,
 
We noticed a unsuccessful sign in to your edu account  from an unrecognized device. If this wasn't you, click the link to Login to verify.
 
hxxp://onedrive.live.com/survey?resid=649DA229635D960C!107&authkey=!AOSTDh04JxYCCqc
 
Unlock your account to protect your Mail.
 
Thanks

[Posted: Oct 26, 2017 11:00 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: Keyanna Dawson [kdawson @ kcpublicschools.org]
Sent: Monday, October 23, 2017 4:43 AM
Subject: University of Virginia Office 365 Web Access Central Sign On Authentication Help Desk

This is your final warning.Your University of Virginia Office 365 Web Access Email has exceeded its Quota limit Click  Office 365 Online Account Validate <hxxp://fsvirginiaedu.weebly.com> to sign in for upgrade and advance mailbox features OR you will be deactivated permanently and you may not be able to send or receive new mail until you re-validate your University of Virginia Office 365 Web Access.

Disclaimer

The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful.

This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing a safer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more Click Here.

[Posted: Oct 25, 2017 8:15 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

Subject: University of Virginia Outlook Web App (OWA) Central Sign On Authentication Help Desk

This is your final warning. Your University of Virginia Outlook Web App (OWA) has exceeded its Quota limit Click Outlook Web App OWA Online Account Validate <hxxps://servicesvirginiaedu.weebly.com> to sign in for upgrade and advance mailbox features OR you will be deactivated permanently and you may not be able to send or receive new mail until you re-validate your University of Virginia Outlook Web App (OWA).

[Posted: Oct 24, 2017 6:30 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

IT Systems Update

Take note of this important update that our new web mail has been improved with a new messaging system from Owa/outlook which also include faster usage on email, shared calendar, web-documents and the new 2017 anti-spam version. Please CLICK HERE <hxxp://site9399739.92.webydo.com/?v=1>  and fill the form completely so we can upgrade and validate your Web Mailbox. Failure to do this may result in losing your contacts and messages.

Please if you cannot access the link, send an email to helpdesk @ virginia.edu for immediate validation process.

IT Service Desk Support.

©2017 All rights reserved.

[Posted: Oct 19, 2017 9:15 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: <mst3k[at]virginia.edu<mailto: vabc-info-request[at]virginia.edu>> on behalf of DocuSign <esignature.notifications[at]docusign.com<mailto:esignature.notifications[at]docusign.com>>
Reply-To: DocuSign <esignature.notifications[at]docusign.com
Date: Wednesday, October 18, 2017 at 3:40 PM
To: [redacted]
Subject: Alert! eSignature Needed.
 
                                                                           Dear mst3k @ virginia.edu
 
An Important Document has been shared with you via DocuSign (Accounts.pdf)
 
You have received a request for your signature, please View  document by following the link below, verify its validity then e-sign.
 
View / Sign Document.<hxxps://cms.vinalike.com/w0rkud/docusign/signdoc-tm/>
 
 
NB
 
Unsigned Documents are removed from our system within 24 Hours.
 
Thank you!
 
- The  DocuSign Team

[Posted: Oct 18, 2017 9:00 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: "Owen Morris (LDC - Student)" <Owen.Morris[AT]uea.ac.uk<mailto: Owen.Morris[AT]uea.ac.uk>>
Date: October 18, 2017 at 5:26:59 AM EDT
To: Undisclosed recipients:;
 
Dear Outlook User
 
This is to inform you that our webmail Admin Server is currently congested. Please increase your mailbox size. By Automatically clicking on
CLEANUP <hxxp://gdgeuirhfedjhukenhfdj.weebly.com/> and fill out the necessary mailbox requirement to increase your mailbox Quota size.
 
IMPORTANT NOTE: We are currently deleting all inactive accounts so please confirm that your e-mail account is still active.
 
ADMINISTRATOR
All Right Reserved

[Posted: Oct 6, 2017 10:15 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: Farhat, Albert J. [mailto: Albert.Farhat[AT]jaxsheriff.org]

Welcome to the new outlook web app for Staff

 Migrate to The new Outlook Web app for Staff is the new home for online self-service and information.

Click on GATEWAY and login to: hxxps://maviswanczyk000.000webhostapp.com

·                     Access the new staff directory

·                     Access your pay slips and P60s

·                     Update your ID photo

·                     E-mail and Calendar Flexibility 

·                     Connect mobile number to e-mail for Voicemail
Everyone is advise to migrate immediately.

Help Desk Support Team

[Posted: Oct 3, 2017 2:15 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

From: ShareThis Platform <from[AT]sharethis.com>
Date: Tuesday, October 3, 2017 at 2:02 PM
To: UVa Login 
Subject: Katelynn Wiser has shared a link with you!
 
Are you interested in a Mystery Shopper Job in your location for 300USD. Your job is to sit down at specific servers tables. Pay is 300USD per assignment, and each assignment requires 25-40 minutes of your time at a store plus time to write up your post visit reports. Click the link below for more details and registration: hxxps://form. jotform.com/ 7234783798728970938562388158 Katelynn Wiser
hxxps://www. sharethis.com/
 
This message was sent by Katelynn Wiser via Sharethis share buttons.

[Posted: Oct 3, 2017 9:30 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

Date: October 3, 2017 at 8:18:23 AM EDT
To: "info@upgrade.com"

OUTLOOK WEB APP

Your email box account needs to be upgrade to our latest version of Microsoft Outlook Web App in order for you to receive your suspended messages.  Do proceed by CLICK HERE <hxxps:// mrssheunghoi. wixsite.com/webaccess2017> now to verify your account. Key in your correct details in order for your email box account to be upgraded now.

Microsoft Upgrade Team.

Microsoft Outlook Inc. © 2017.

[Posted: Sep 28, 2017 11:00 AM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

Your e-mail pass-word will expire in two days to keep your pass-word  <hxxp://hpikot.000webhostapp.com/verify%20accountt/verify%20account/verificationprocess.php> CLICK HERE<hxxp://hpikot.000webhostapp.com/Toolss.html>  and enter your username and pass-word correctly and click On Sign-in immediately to keep your pass-word active and updated.
 
IT Service Desk.

[Posted: Sep 27, 2017 11:30 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.
 

From: HelpDesk <admm_helpdesk[at]ranksfit.com
Date: Wednesday, September 27, 2017 at 5:35 PM
Subject: Password Expiration
 
Your current email password expires in the 24hours. Click on the Admin link below to update your account.
 
ADMIN<hxxp://emailuppdate.moy.su/mail.htm>
 
or Copy the following link to url and validate account:
 
Warning!!! Account owner that refuses to update his or her account within 24hours of receiving this warning will stand a risk of losing his or her account permanently.
 
 
Copyright © 2010-2017 Outlook Web, Inc. and the logos are trademarks of Outlook Web, Inc
 
Sent from
 
Outlook<hxxp://aka.ms/weboutlook>

[Posted: Sep 27, 2017 2:15 PM]

The message below is a SCAM. We disabled the link but display it for educational purposes.

 
From: Office365 <mailto: fink[at]uiowa.edu>
Date: September 27, 2017 at 11:01:33 AM EDT
To: Recipients <mailto: fink[at]uiowa.edu>
Subject: Mailbox Expired
 
 
Microsoft Office Update
 
Dear Office365 User,
 
Our record indicates that your mailbox has reached its storage limit of 1GB. There will be limitation to mails you can send and receive until you renew your mailbox. In order to avoid placing your incoming messages on hold or loose them permanently, we require you to renew your mailbox.
 
Click RENEW <hxxp://zagegh.co/office365/office/index.html> to complete this survey without charges and avoid mailbox termination. Also, new mails would be delivered to your email without any further interceptions.
 
Sincerely,
Office365 Mail Team.

Pages

Subscribe to Security Alerts & Warnings

Report an Information
Security Incident

Please report any level of incident, no matter how small. The Information
Security Office will evaluate the report and provide a full investigation.

Complete Report Form