Lately we have seen many users receive an email with the subject line of Important Document, Pending Document, Review & Sign Document, or something similar that when opened appears to be from Dropbox or another similar cloud document hosting service. When the user clicks the Review & Sign Document button it then prompts you to log in with an email account, but once you enter your BearID & password nothing happens…until your account starts sending phishing emails out to more users. Below is a picture of the phishing email we have seen on campus most recently.
It all starts with the awareness of the risks along with the realization that everybody is a potential target. Much of what we do every day involves the internet positively in one way or another.