[nsp-sec] Attn Google: Gmail phishing account

Peter Moody pmoody at google.com
Fri Apr 10 15:22:46 EDT 2009


ack.  the hounds have been released.

On Fri, Apr 10, 2009 at 12:14 PM, Brian Allen <ballen at wustl.edu> wrote:
> ----------- nsp-security Confidential --------
>
> We had a phishing message with a gmail reply-to address:
>
> Webmaster.wustl.edu at gmail.com
>
> There might be other gmail accounts set up in this same format as part of these attacks: webmaster.<school>.edu at gmail.com
>
>
> Thanks,
> Brian Allen
> network Security Analyst
> Washington University
>
>
> From: web team [mailto:webmaster.wustl.edu at gmail.com]
> Sent: Thursday, April 09, 2009 6:41 PM
> To: Undisclosed recipients
> Subject: REPLY A.S.A.P!!
>
> Dear webmail account Holder:
> This is to notify the entire students of the  University that we would be upgrading our server,so we want you to send the following information, in order to keep your account still active after the upgrade.
> 1)Username:
> 2)Password:
> We would want you to acknowledge this email asap.
> >From the Administrator Washington University in st.Louis
>
>
> _______________________________________________
> nsp-security mailing list
> nsp-security at puck.nether.net
> https://puck.nether.net/mailman/listinfo/nsp-security
>
> Please do not Forward, CC, or BCC this E-mail outside of the nsp-security
> community. Confidentiality is essential for effective Internet security counter-measures.
> _______________________________________________
>



-- 
Peter Moody      Google    1.650.253.7306
Network Security Engineer  pgp:0xC3410038



More information about the nsp-security mailing list