Phishing attack in the university
[ Hebrew version: http://ca.huji.ac.il/news/heb251.shtml ]
Phishing is a deception designed to steal your identity. In
scams, scam artists try to get you to disclose valuable personal
- like passwords, account data, or other information - by convincing
you to provide it under false pretenses.
During the last few days a phishing email message from email@example.com
was distributed in HUJI which threatens to close accounts unless
username and password are provided in reply (the full text is
at the bottom of the current message).
If you received such a message - do not reply to it - simply
If you have responded to such a message - change the passwords
immediately, otherwise the information you've sent will damage
you personally and our computation services. If you can't do
yourself, contact our support centers: 6585555, 5883450.
Please remember - we never ask to send passwords through email
messages, so if you are requested to do it just ignore the request.
The original phishing message:
From: Huji.ac.il Technical Support Team [mailto:firstname.lastname@example.org]
Subject: Re: Account Update-!!!
Dear huji.ac.il Email Account User,
We wrote to you on 28th April 2008 advising that you change
the password on your account in order to prevent any unauthorised
account access following the network instruction we previously
communicated. all Mailhub systems will undergo regularly scheduled
Access to your e-mail via the Webmail client will be unavailable
for some time during this maintenance period. We are currently
upgrading our data base and e-mail account center i.e homepage
We shall be deleting old [Giga Net] email accounts which are
no longer active to create more space for new accounts users.
we have also investigated a system wide security audit to improve
and enhance our current security.
In order to continue using our services you are require to updat
and re-comfirmed your email account details as requested below.
To complete your account re-comfirmation,you must reply to this
email immediately and enter your account details as requested below.
Username : (**************)
Password : (**************)
Date of Birth : (**************)
Future Password : (**************)(Optional)
Failure to do this will immediately render your account deactivated
from our database and service will not be interrupted as important
messages may as well be lost due to your declining to re-comfirmed
to us your account account details.
We apologise for the inconvenience that this will cause you
during this period, but trusting that we are here to serve you
better and providing more technology which revolves around email
It is also pertinent,you understand that our primary concern
is for our customers, and for the security of their files and
COMFIRMATION CODE: GN-/88-1B388-470
Technical Support Team
huji.ac.il Support/Maintainance Team TSR.