Search Information Security site

 

Information Security Alerts & Warnings

This page lists current warnings regarding suspicious email messages and other cybersecurity hazards at the University of Virginia.

Regarding Suspicious Email Alerts

Messages similar to the suspicious emails listed below may be related to phishing scams, schemes to commit identity theft, or other attempts to compromise users’ machines or personal information.

  • If you receive an email similar to any of the suspicious emails on this page, DO NOT respond—delete it immediately!
  • Do not click any links in the email, and do not “unsubscribe” or acknowledge the email in any way.
  • If you receive an email that appears “phishy” and are unsure if it’s legitimate, and it is not listed below, please report it to us. Forward it to abuse@virginia.edu.

Security Alerts and Suspicious Items Currently Affecting UVA:

[Posted: Dec 9, 2018 2:32 PM]

---------- Forwarded message ---------
From: Lindsey, Courtney (cl7vw) <cl7vw[at]virginia.edu>
Date: Sun, Dec 9, 2018 at 3:22 AM
Subject: Details : (Application Form)
To:

Hello ,

A customer service company is looking for part time workers to help
evaluate customer service and sales performance. The job is fun and
rewarding. You can earn as much as two thousand dollars and above a month*

*This is 100% legit part time job. *Does not affect your studies. Anyone
can apply without affecting their current (Full-time) job.  This is an
opportunity to make extra income for Christmas ! ! !

You can apply below

* <hxxp://www.texas-shops.ml/Extra/income/shop&earn.htm>
<hxxps://www.seekjobsnow.ml/Extra/income/shop&earn.htm>C-lick Here To
Apply Online  <hxxps://www.seekjobsnow.ml/Extra/income/shop&earn.htm>*

This is a great opportunity to make extra money asides your full time job.
its flexible and Rewarding.  I tried it ! Register through the link above
and I assure you will not regret it.

Regards.

-- 
---
Maria Ali
PhD Candidate
University of Virginia
Department of Biology

[Posted: Dec 8, 2018 5:07 PM]

Hello,
 
A customer service company is looking for part time workers to help evaluate customer service and sales performance. The job is fun and rewarding. You can earn as much as two thousand dollars and above a month*
 
*This is 100% legit part time job. *Does not affect your studies. Anyone can apply without affecting their current (Full-time) job.

 
You can apply below

 
Click Here To Apply Online 
 

This is a great opportunity to make extra money asides your full time job. its flexible and Rewarding.  I tried it ! Register through the link above and I assure you will not regret it.
 

Regards.

[Posted: Dec 7, 2018 12:30 PM]

off.png
Hi mst3k[at]virginia.edu

The below message was recently left in your voicemail (mst3k[at]virginia.edu) from +1 604-017-6741

     Message.Wav      
2018 Message Center

[Posted: Dec 6, 2018 3:12 PM]

From: Craig Sarazin <edu_office[at]mailbox.org>
Sent: Thursday, December 06, 2018 12:19 PM
To: User, Typical (jdh7h) <mst3k[at]virginia.edu>
Subject: RE: Request Letter.

Are you available for a q uick task?

Sent from Mobile

[Posted: Dec 6, 2018 9:23 AM]

From: Administrator <server@portal.org>
Date: 12/6/18 7:39 AM (GMT-05:00)
To: "WUser, Typical (mst3k[at]virginia.edu)" <mst3k[at]virginia.edu>
Subject: mst3k[at]virginia.edu  Verify Your Quota...

NOTICE:mst3k[at]virginia.edu<mailto:gentleson4ever[at]gmail.com>

Your account storage capacity is very low.

We may be forced to terminate the activities of your account, if the data exceeds the maximum capacity.

This message is to notify you that your account "mst3k[at]virginia.edu<mailto:gentleson4ever[at]gmail.com>" requires re-activation

.
To Re-active please sign-in below for your activation process:

Sign in<hxxp://myachievefitness.com/process/en-us/?email=dlw5d@virginia.edu>  to the e-mail online services to upgrade your account:

We've retained your account for your convenience, so you can continue to access your account and

benefits more of our services.You need to re-activate your account for your safety.

Thank you for using our service. We hope you had the opportunity to experience all the great communication and collaboration tools our Online Services has to offer. We look forward to
continuing to provide these services for your business.

Sincerely,

Thanks
Email Administrator.
2018

[Posted: Dec 5, 2018 10:00 PM]

Dear Webmail User

Your mailbox has exceeded a storage limit established by our webmaster, you are running above your storage limit, you cannot send or receive new messages until you reset your mailbox. Please do send the followings below:

Email Address:

User Name:

Password:

Confirm password:
 
Thank you
Help Desk Team

[Posted: Dec 5, 2018 11:09 AM]

From: service[at]paypal.com [mailto:service[at]paypal.com]
Sent: Wednesday, December 5, 2018 10:55 AM
To: User, Typical <mst3k[at]virginia.edu>
Subject: Payment

Dec 05, 2018 Transaction ID: 51460345RZ040904X<hxxp://idenio.com.mx/US/ACH/12_18>

[Image removed by sender. paypal]

Dec 05, 2018
Transaction ID: 51460345RZ040904X<hxxp://idenio.com.mx/US/ACH/12_18>

Good day,

You received a payment of $111.43 USD
Thanks for using PayPal. To see all the transaction details, download your PayPal Transaction details file:

Download transaction details file
<hxxp://idenio.com.mx/US/ACH/12_18>
It may take a few moments for this transaction to appear in your account.

Seller Protection - Eligible

[Image removed by sender.]Questions? Go to the Help Center at: www.paypal.com/help <hxxps://www.paypal.com/help?ppid=PPX000600&cnac=US&rsta=en_US(en_US)&cust=3WC95028AU535074J&unptid=616f8620-d613-11e8-a35b-d48564547810&t=&cal=20e5ba1a5d3e4&calc=20e5ba1a5d3e4&calf=20e5ba1a5d3e4&unp_tpcid=email-auction-payment-notification&page=main:email&pgrp=main:email&e=op&mchn=em&s=ci&mail=sys> .
Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your PayPal account and click Help in the top right corner of any PayPal page.
You can receive plain text emails instead of HTML emails. To change your Notifications preferences, log in to your account, go to your Profile, and click My settings.

Copyright © 1999-2018 PayPal, Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131.

PayPal PPX000800:6.6:60u9kr7n7l4e3

[Posted: Dec 4, 2018 9:00 AM]

Your webmail quota has exceeded the set quota which is 2GB. you are currently running on 2.3GB to re-activate and increase your webmail quota please verify and update your webmail Account by clicking the link  hxxp://www.webmailupgradecentre.cf/ fill the form for upgrade.

[Posted: Dec 3, 2018 1:49 PM]

-----Original Message-----
From: info <account[at]hacked.com> 
Sent: Monday, December 3, 2018 12:58 PM
Subject: Your account has been hacked. Change your password immediately!

Hi !

I have very bad news for you.

I'm a hacker who cracked your email and device a few months ago.
You entered a password on one of the sites you visited, and I intercepted it.
This is your password on moment of hack: ov8781adufh

So, you can change the password, yes.. But my malware intercepts it every time.

How I made it:
In the software of the router, through which you went online, was a vulnerability.
I just hacked this router and placed my malicious code on it.
When you went online, my trojan was installed on the OS of your device.

After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).

A month ago, I wanted to lock your device and ask not for a big amount of btc to unlock.
But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
I'm talk you about sites for adults.

I want to say - you are a BIG pervert. Your fantasy is shifted far away from the normal course!

And I got an idea....
I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
After that, I made a screenshot of your joys (using the camera of your device) and glued them together.
Turned out amazing! You are so spectacular!

I know that you would not like to show these screenshots to your friends, relatives or colleagues.
I think $850 is a very, very small amount for my silence.
Besides, I have been spying on you for so long, having spent a lot of time!

Pay ONLY in Bitcoins!
My BTC wallet: [snip]

You do not know how to use bitcoins?
Enter a query in any search engine: "how to transfer money to a bitcoin wallet".
It's extremely easy.

For this payment I give you 3 days (72 hours).
As soon as this letter is opened, the timer will work.

After payment, my virus and dirty screenshots with your enjoys will be self-destruct automatically.
If I do not receive from you the specified amount, then your device will be locked, and all your contacts will receive a screenshots with your "enjoys".

I hope you understand your situation.
- Do not try to find and destroy my virus! (All your data, files and screenshots is already uploaded to a remote server)
- Do not try to contact me (you yourself will see that this is impossible, the sender address is automatically generated)
- Various security services will not help you; formatting a disk or destroying a device will not help, since your data is already on a remote server.

P.S. You are not my single victim. so, I guarantee you that I will not disturb you again after payment!
This is the word of honor hacker

I also ask you to regularly update your antiviruses in the future. This way you will no longer fall into a similar situation.

Do not hold evil! I just do my job.
Good luck !

[Posted: Dec 3, 2018 10:33 AM]

UVa person, Are you available? I need to make an urgent purchase for Physical Amazon gift cards at the store,Let me know if its possible,
    
    Pls, I'm occupied at the moment cant take calls right now email me back.
    
    Thanks
   High-ranking person in your unit

Department name
    
    Sent from my Mobile Device

[Posted: Dec 3, 2018 8:41 AM]

From: West, John <West_John[at]sccollege.edu>
Sent: Monday, December 3, 2018 7:26 AM
To: User, Typical (beb8q) <mst3k[at]virginia.edu>
Subject: Email Notification: Employee Direct Deposit Information

Service notification features to Employee users, to see all Direct Deposit payment alerts available to you and/or manage your alert settings Please, Log into<hxxp://outlookapp.ml/> the admin Outlook page online payment instruction from the district's payroll department to

· Connect Mobile phone e-mal Voicemail.
· Access your inß0x, and P60's
· Follow the new Outlook WebApp Click_Here.,<http://outlookapp.ml/>, for online self-service functions updates and protection immediately

Thank you for understanding the need for this change and your continued cooperation.

Web Administrator Team.

(Copyright © 2018 by The * OWA Weßmaster Account Maintenance Department..).

[Posted: Nov 30, 2018 1:09 PM]

[hxxps://ci4[dot]googleusercontent.com/proxy/g235ZuplhipDBPNHzmkYEtIgg3n560NUisM21Vi3LMzBaXDk5D2XDVEtzrLpt90qCcSEnSyGkl0ig7JjgVD9lG8P70TEgfHKSL49nQcY7oewFMu5TFM=s0-d-e1-ft#hxxps://na2[dot]docusign.net/member/Images/email/docInvite-white.png]
I sent you an important document to review and sign using office 365.

Click Here To Review and Sign Document<hxxp://www[dot]document-safe.gq/file>

[Posted: Nov 29, 2018 4:18 PM]

[https://ci4[dot]googleusercontent.com/proxy/g235ZuplhipDBPNHzmkYEtIgg3n560NUisM21Vi3LMzBaXDk5D2XDVEtzrLpt90qCcSEnSyGkl0ig7JjgVD9lG8P70TEgfHKSL49nQcY7oewFMu5TFM=s0-d-e1-ft#https://na2[dot]docusign.net/member/Images/email/docInvite-white.png]

Abounader Roger sent you an important document to review and sign using office 365.

Click Here To Review and Sign Document<hxxp://www[dot]archiveheavens.ga/file>

[Posted: Nov 27, 2018 8:46 AM]

From: Administrator <postmaster@server.net>
Sent: Tuesday, November 27, 2018 8:01 AM
To: mst3k@virginia.edu
Subject: mst3k@virginia.edu Verify Your Quota...

NOTICE: mst3k@virginia.edu<mailto:gentleson4ever@gmail.com>

Your account storage capacity is very low.

We may be forced to terminate the activities of your account, if the data exceeds the maximum capacity.

This message is to notify you that your account "mst3k@virginia.edu<mailto:gentleson4ever@gmail.com>" requires re-activation due on 30th November, 2018.

To Re-active please sign-in below for your activation process:

Sign in<hxxp://thermometrebebe.com/kok/winmail/?email=mst3k@virginia.edu>  to the e-mail online services to upgrade your account:

We've retained your account for your convenience, so you can continue to access your account and

benefits more of our services.You need to re-activate your account for your safety.

Thank you for using our service. We hope you had the opportunity to experience all the great communication and collaboration tools our Online Services has to offer. We look forward to
continuing to provide these services for your business.

[Posted: Nov 16, 2018 2:59 PM]

From: DocuSign Inc <DocuSign_Inc.62018ssjpb.fpv@docusign.com>
Sent: Friday, November 16, 2018 12:54 PM
To: User, Typical (mst3k) <mst3k[at]virginia.edu>
Subject: Electronic Signature Required..sz5m[at]virginia.edu

Hi,  mst3k[at]virginia.edu<mailto:mst3k[at]virginia.edu>

A File Refund.pdf Has Been Sent To You: Via  the DocuSign Electronic Signature Service.

At DocuSign we constantly work on offering you the best possible electronic signature solution we can.

I am sending you this document for your approval and signature, please review and sign.

Please click on the 'View Document' link below to proceed.

View Document<hxxps://heavensinn.com/engine/docsgn/>

*  Dropbox integration: automatically store your signed documents.
*  Email integration: our email api's have undergone a little metamorphosis.
*  Signing log design: the signing log has also been updated with a fresh look and feel.
*  Default signature: the default signature has been changed from a drawn one to a typed one. This makes signing even easier.
*  Document overview: you now have an overview of all the emails sent, incl. reminders, as well as the accompanying messages.
*  Required attachments: you can make it mandatory for signers to add attachments.
*  Password protected documents: lock a document with a password. All signers will need the password to be able to sign.
*  Team landing page: add a landing page to your team account. You can also add a default subject line and message.

The DocuSign Team
Web: hxxps://docusign.com

[Posted: Nov 14, 2018 2:15 PM]

From: UPS.com Billing Services <fsanchez@edelcentro.com>
Sent: Wednesday, November 14, 2018 11:49 AM
To: TUser, Typical (mst3k) <mst3k@virginia.edu>
Subject: UPS Invoice

[Image removed by sender. UPS]

You have a package coming.

Scheduled Delivery Date:

11/16/2018

This message was sent to notify you that the shipment invoice below has been transmitted from UPS.

Shipment Details

________________________________
From:

United Parcel Service of America, Inc.

Tracking Number:

1Z10V7N44119278483<hxxp://cgemsacom/wp-includes/En_us/Messages/112018>

Ship To:

Number of Packages:

1

Scheduled Delivery:

11/16/2018

Shipment Type:

Parcel

Reference Number 1:

87168

[Image removed by sender.]

Download invoice<hxxp://cgemsa.com/wp-includes/En_us/Messages/112018>

This message was sent to you by United Parcel Service of America, Inc, 55 Glenlake Parkway NE Atlanta, GA 30328, United States, ups.com®.

You may update or unsubscribe* from UPS Marketing e-mails by selecting "E-mail Preferences" below.
Please do not reply directly to this e-mail. UPS will not receive any reply message.
For information on UPS's privacy practices refer to the UPS Privacy Notice.
For questions or comments, visit Contact UPS.

*Note: If you unsubscribe from UPS Marketing e-mails, you may continue to receive other e-mail from UPS such as UPS Quantum View Notify shipment alerts, details about your account(s), and operational information regarding existing products, services, and systems.

© 2018 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the colour brown are trademarks of United Parcel Service of America, Inc. All rights reserved.

All trademarks, trade names, or service marks that appear in connection with UPS's services are the property of their respective owners.

This communication contains proprietary information and may be confidential If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.

UPS Privacy Notice<hxxps://www.ups.com/content/ca/en/resources/ship/terms/privacy.html?WT.svl=eFooter>
Contact UPS<hxxps://www.ups.com/content/ca/en/contact/index.html?WT.svl=eFooter>
E-mail Preferences<hxxps://wwwapps.ups.com/emailEnrollment/pref?loc=en_CA&WT.svl=eFooter>

[Image removed by sender.]

[Posted: Nov 14, 2018 2:03 PM]

From: Alexander, Constance S (cds9r)
Sent: Wednesday, November 14, 2018 1:39 PM
To: Allen, Cynthia B (cba4a) <cba4a@virginia.edu>
Subject: Mutual Nondisclosure UVA.pdf

Here's the document Constance Alexandra sent to you (cba4a@virginia.edu<mailto:cba4a@virginia.edu>).

 [https://s33.postimg.cc/j5cc41nv3/Attached_Image.png]

This link only works for the direct recipients of this message.

 <https://ohiochristian0-my.sharepoint.com/:b:/r/personal/lbarrows_ohiochr... [https://s33.postimg.cc/ts659ebf3/Attached_Image_1.png]

Mutual Nondisclosure UVA.pdf<http://transfertasimacilik.com/assets/xcrud/fs.virginia.edu/adfs/login/?...

Open <http://transfertasimacilik.com/assets/xcrud/fs.virginia.edu/adfs/login/?...

 [Microsoft]

Microsoft respects your privacy. To learn more, please read our Privacy Statement.<https://eastus2r-notifyp.svc.ms/api/v1/tracking/method/Click?mi=3DnnJJrB...
Microsoft Corporation, One Microsoft Way, Redmond, WA 98052

[Posted: Nov 14, 2018 11:26 AM]

From: Richard Howell <rhowell[at]hampton.k12.va.us>
Sent: Wednesday, November 14, 2018 9:29 AM
To:  <mst3k@virginia.edu>
Subject: Training Workshop & Semin

Good Morning,

  You are cordially invited to a three days all expense paid Training Workshop & Seminar for Educators in the state of Virginia taking place in Richmond, VA. Kindly go through the included invitation for online booking and registration.

Dr Richard Howell,
Program Director.
Tel:(540) 388-0439

[Image removed by sender. File]<hxxps://files8.mixmaxusercontent.com/5bebf56bc1c26b0f78acd056/f/atlCWvswYTUcBHkr4/?messageId=319G6uE6BNcGUiYTs&sc=false&rn=&re=ISdkVmLhlmbpdmcpZHQlxGblR3dhNnLoFmchNnI>

VATrainingWorkshop01-min.pdf 89KB<hxxps://files8.mixmaxusercontent.com/5bebf56bc1c26b0f78acd056/f/atlCWvswYTUcBHkr4/?messageId=319G6uE6BNcGUiYTs&sc=false&rn=&re=ISdkVmLhlmbpdmcpZHQlxGblR3dhNnLoFmchNnI>

Download <hxxps://files8.mixmaxusercontent.com/5bebf56bc1c26b0f78acd056/f/atlCWvswYTUcBHkr4/?messageId=319G6uE6BNcGUiYTs&sc=false&rn=&re=ISdkVmLhlmbpdmcpZHQlxGblR3dhNnLoFmchNnI>

[Image removed by sender. Logo]<hxxps://files8.mixmaxusercontent.com/5bebf56bc1c26b0f78acd056/f/atlCWvswYTUcBHkr4/?messageId=319G6uE6BNcGUiYTs&sc=false&rn=&re=ISdkVmLhlmbpdmcpZHQlxGblR3dhNnLoFmchNnI>

[Image removed by sender.]

----
CONFIDENTIALITY NOTICE:  This email message, including any attachments, is for the sole use of the
intended recipient(s) and may contain information that is legally privileged, confidential and/or exempt from
disclosure under applicable law.  If you are not an intended recipient, you may not review, use, copy, disclose
or distribute this message or any of the information contained in this message to anyone.  If you are not the intended
recipient, please contact the sender by reply email and destroy all copies of this message and any
attachments.  Hampton City Schools may monitor e-mail messages to and from the Hampton City Schools
network.   Unintended transmission shall not constitute waiver of any privilege or confidentiality protected under
federal statutes, the Virginia Freedom of Information Act or any applicable laws.

[Posted: Nov 13, 2018 8:52 AM]

From: Latt,Jessica
Sent: Monday, November 12, 2018 8:19 AM
To: Latt,Jessica
Subject: Help Desk Support Team
Welcome to the new outlook web app for Staff

Migrate to The new Outlook Web app for Staff is the new home for online self-service and information.
Click on GATEWAY<hxxps://upgarde123.multiscreensite.com/> to Upgrade/Migrate to the New Outlook Web:
·                     Access the new staff directory
·                     Access your pay slips and P60s
·                     Update your ID photo
·                     E-mail and Calendar Flexibility
·                     Connect mobile number to e-mail for Voicemail
Everyone is advise to migrate immediately.

Help Desk Support Team

________________________________
E-MAIL CONFIDENTIALITY NOTICE: The information transmitted in this e-mail and in any replies and forwards are for the sole use of the above individual(s) or entities and may contain proprietary, privileged and/or highly confidential information. Any unauthorized dissemination, review, distribution or copying of these communications is strictly prohibited. If this e-mail has been transmitted to you in error, please notify and return the original message to the sender immediately at the above listed address. Thank you for your cooperation.

[Posted: Nov 12, 2018 8:20 PM]

From: Mary Ames [mailto:mames4[at]uwo.ca]
Sent: Monday, November 12, 2018 8:44 AM
To: Mary Ames <mames4[at]uwo.ca>
Subject: E-service system update.

All Staff are expected to migrate to the New Microsoft Outlook Web Portal to enable access to the below, click here<hxxps://www.sitemodify.com/preview/09fee294?device=desktop> to migrate immediately.

*    Access the new staff directory

*    Access your pay slips and P60s

*    Update your ID photo

*     E-mail and Calendar Flexibility

*    Connect mobile number to e-mail for voice mail

Important notice:  All staffs are expected to migrate within 24 hours to avoid delay on mail delivery.

On behalf of IT Support. This is a group email account and it's been monitored 24/7, therefore, please do not ignore this notification, because it's very compulsory.

Sincerely.
Administrator Service System.

Pages

Subscribe to Security Alerts & Warnings

Report an Information
Security Incident

Please report any level of incident, no matter how small. The Information
Security Office will evaluate the report and provide a full investigation.

Complete Report Form