<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Outlook phishing in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Outlook-phishing/m-p/41512#M152</link>
    <description>&lt;P&gt;OK, this is a new one on me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got an email in one of my Outlook accounts. It said that a request had been made to cancel that particular Outlook account. Supposedly the email was from Outlook, and it had Microsoft logos and everything. It looked pretty legit, although it sounded really strange that someone would be able to request cancellation of my account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the headers seemed to indicate that it had come from outlook.com.gr. Why should Microsoft be handling its email accounts out of Greece?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course it had a link in the body of the message to cancel the cancellation. That showed, on the face of it, that it was at Outlook. However, the link really went to a specific directory and file at &lt;A href="https://ia601508.us.archive.org" target="_blank"&gt;https://ia601508.us.archive.org&lt;/A&gt;. Looking (carefully) at the link displayed a graphic that seemed to indicate that my account was being deactivated, although it never actually got to the end of its progress bar. And, of course, there was a big red "Cancel Deactivation" button which, when pressed, asked for my password to verify that it was me. Simple phishing, trying to steal my Outlook account.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:43:37 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2023-10-09T09:43:37Z</dc:date>
    <item>
      <title>Outlook phishing</title>
      <link>https://community.isc2.org/t5/Threats/Outlook-phishing/m-p/41512#M152</link>
      <description>&lt;P&gt;OK, this is a new one on me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got an email in one of my Outlook accounts. It said that a request had been made to cancel that particular Outlook account. Supposedly the email was from Outlook, and it had Microsoft logos and everything. It looked pretty legit, although it sounded really strange that someone would be able to request cancellation of my account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the headers seemed to indicate that it had come from outlook.com.gr. Why should Microsoft be handling its email accounts out of Greece?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course it had a link in the body of the message to cancel the cancellation. That showed, on the face of it, that it was at Outlook. However, the link really went to a specific directory and file at &lt;A href="https://ia601508.us.archive.org" target="_blank"&gt;https://ia601508.us.archive.org&lt;/A&gt;. Looking (carefully) at the link displayed a graphic that seemed to indicate that my account was being deactivated, although it never actually got to the end of its progress bar. And, of course, there was a big red "Cancel Deactivation" button which, when pressed, asked for my password to verify that it was me. Simple phishing, trying to steal my Outlook account.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:43:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Outlook-phishing/m-p/41512#M152</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2023-10-09T09:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Outlook phishing (and other kinds)</title>
      <link>https://community.isc2.org/t5/Threats/Outlook-phishing/m-p/41885#M180</link>
      <description>&amp;gt; Keyshawn (Viewer) posted a new reply in Threats on 12-22-2020 01:14 AM in the (ISC)Â² Community :&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Your submission really means a lot to us, and we hope you will continue&lt;BR /&gt;&amp;gt; contributing to this subreddit whether it is in the form of an informative&lt;BR /&gt;&amp;gt; post or an opinion piece. Please be sure to have read our&amp;nbsp;Rules of&lt;BR /&gt;&amp;gt; Conduct&amp;nbsp;and do not try to circumvent it. That means that any reference to&lt;BR /&gt;&amp;gt; 3rd party commercial products/services as a solution is strictly prohibited&lt;BR /&gt;&amp;gt; and will result in a permanent ban in this subreddit. Under very exceptional&lt;BR /&gt;&amp;gt; circumstances, you may appeal to the ban in a case-by-case basis.&lt;BR /&gt;&lt;BR /&gt;OK, this sounds like a bot, and, since he/it only joined a short while ago, it looks&lt;BR /&gt;like a bot as well. Note that, during the pandemic, we have seen a massive&lt;BR /&gt;increase in all kinds of spam and fraud and phishing. I had at least three separate&lt;BR /&gt;"Amazon Prime" phone robocalls last night (and I have *never* had an Amazon&lt;BR /&gt;Prime account). Please be careful, and tell all your friends and family to be&lt;BR /&gt;careful, too: the blackhats are out there in force these days.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;Although the world is full of suffering, it is also full of the&lt;BR /&gt;overcoming of it. - Helen Keller&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Tue, 22 Dec 2020 18:14:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Outlook-phishing/m-p/41885#M180</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-12-22T18:14:18Z</dc:date>
    </item>
  </channel>
</rss>

