“Voicemessage Notification” email is actually a phishing scam

Posted by Akankasha Dewan on 14 June 2019 12:53:19 AEST

As cybercrime evolves in complexity daily, cybercriminals are coming up with new and innovative ways of fooling unsuspecting Web users and infecting their systems.

MailGuard has detected a new phishing email scam that masquerades as a “Voicemessage Notification”. Sent via a compromised account, the ‘From’ field in the email message is a long VM notification display name, with parts of a phone number.

While we have detected some variations on the message body, they all contain a similar message. Advising the recipient that they have received a new voice message, the emails direct them to click on an included link to view, listen or save the file.

Here are 2 different variations regarding the email message:

VM2VM1

Unsuspecting recipients who click on the file link are led to to an Outlook branded phishing page. The users are first asked to enter their email address, as per the below:

VM email message

They are then asked to enter their password:

VM password

Once the form is completed the first time, they are sent back to the first page (asking for their email address) with a message stating that their email address and/or password is incorrect (as per the below screenshot):

Outlook_Thumbnail

Once this information is entered a second time, they are redirected to the actual Office 365 login page.

Despite the impersonation of Outlook’s logo and branding, eagle-eyed recipients would be able to identify the inauthenticity of the email due to several red flags. These include the fact that the email body in itself isn’t well-formatted and contains grammatical & spacing errors, and the fact that the ‘from’ field suspiciously contains multiple numbers.

Whilst MailGuard is stopping this email scam from reaching Australian businesses, we encourage all users to be extra vigilant against this kind of email and whatever happens, do not open or click them.

Phishing continues to be one of the most prevalent forms of cyber-crime. The vast majority of online scams - more than 90% - are perpetrated using email, so it’s wise to always be skeptical of messages from unfamiliar senders asking you to log into your accounts.

What to look out for

As a precaution, avoid clicking links in emails that:

  • Are not addressed to you by name, have poor English or omit personal details that a legitimate sender would include (e.g. – tracking ID).
  • Are from businesses you’re not expecting to hear from.
  • Ask you to download any files, especially with an .exe file extension.
  • Take you to a landing page or website that does not have the legitimate URL of the company the email is purporting to be sent from.

One email


Cybercriminals use email scams to infiltrate organisations with malware and attack them from the inside. 
All criminals need to break into your business is a cleverly worded message. If they can trick one person in your company into clicking on a malicious link they can gain access to your data.

For a few dollars per staff member per month, you can protect your business with MailGuard's predictive email security.
Talk to an expert at MailGuard today about making your company's network secure: click here.

 

Stay up-to-date with new posts on the MailGuard Blog by subscribing to free updates. Click on the button below:

Keep Informed with Weekly Updates

 

 



Topics: Xero

Back to Blog

Comments:


Something Powerful

Tell The Reader More

The headline and subheader tells us what you're offering, and the form header closes the deal. Over here you can explain why your offer is so great it's worth filling out a form for.

Remember:

  • Bullets are great
  • For spelling out benefits and
  • Turning visitors into leads.

Recent Posts

Posts by Topic

see all