{"id":486,"date":"2018-12-05T09:03:53","date_gmt":"2018-12-05T14:03:53","guid":{"rendered":"http:\/\/pages.vassar.edu\/catchoftheday\/?p=486"},"modified":"2018-12-05T09:04:32","modified_gmt":"2018-12-05T14:04:32","slug":"someone-sent-you-files-via-wetransfer","status":"publish","type":"post","link":"https:\/\/pages.vassar.edu\/catchoftheday\/someone-sent-you-files-via-wetransfer\/","title":{"rendered":"Someone sent you files via WeTransfer"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-487\" style=\"border: 2px solid #0000ff;padding: 1px;margin: 1px\" src=\"http:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer1.jpg\" alt=\"\" width=\"600\" height=\"857\" srcset=\"https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer1.jpg 600w, https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer1-210x300.jpg 210w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-488\" src=\"http:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer2.jpg\" alt=\"\" width=\"600\" height=\"510\" srcset=\"https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer2.jpg 600w, https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer2-300x255.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-489\" src=\"http:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer3.jpg\" alt=\"\" width=\"600\" height=\"578\" srcset=\"https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer3.jpg 600w, https:\/\/pages.vassar.edu\/catchoftheday\/files\/2018\/12\/Dec4WeTransfer3-300x289.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p><!--more--><\/p>\n<h2>Why this looks valid<\/h2>\n<ul>\n<li style=\"font-weight: 400\">The email came from a company that the college does business with.<\/li>\n<li>It is common for companies to send invoices or other information through a file sharing platform.<\/li>\n<li>WeTransfer is a valid document sharing site.<\/li>\n<\/ul>\n<h2>Why this is phishing<\/h2>\n<ul>\n<li>The shared document is a PDF that launches another website, which does <em>not<\/em> go to the company or any known website.<\/li>\n<li>The link asks to select a login service and then launches a login screen that does not resemble any Vassar College login screens.<\/li>\n<li style=\"font-weight: 400\">We&#8217;ve seen this one before! The method of sending a PDF with an embedded link that then launches a phishing site is becoming increasingly common.\u00a0 Review previous Catch of the Day posts to see more examples.<\/li>\n<\/ul>\n<h2>Additional notes<\/h2>\n<ul>\n<li style=\"font-weight: 400\">This is an extremely dangerous Phishing attempt. If you clicked on this link and may have completed the form, please contact the Service Desk immediately at x7224 or <a href=\"mailto:servicedesk@vassar.edu\">servicedesk@vassar.edu<\/a><\/li>\n<li>Protect your accounts with multi-factor authentication! If you do click on a phishing link and your Vassar credentials get compromised, attackers won\u2019t be able to login: <a href=\"http:\/\/pages.vassar.edu\/catchoftheday\/2017\/06\/29\/best-practice-enabling-multi-factor-authentication-with-duo\/\">http:\/\/pages.vassar.edu\/catchoftheday\/2017\/06\/29\/best-practice-enabling-multi-factor-authentication-with-duo\/<\/a><\/li>\n<li style=\"font-weight: 400\">Always examine the link! Look at the information in your web browser to determine whether or not the site you are directed to is a Vassar site or an unknown (or suspicious) one.<\/li>\n<li style=\"font-weight: 400\">A phone call to the alleged sender would quickly verify if this is a legitimate email. It only takes a few minutes to pick up the phone!<\/li>\n<li style=\"font-weight: 400\">Report it as phishing to Google. Before deleting the message, make sure to click on \u201creport phishing&#8221;.<\/li>\n<li style=\"font-weight: 400\">A little paranoia goes a long way! Be suspicious of any email messages similar to this one.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":8,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[80936],"tags":[],"class_list":["post-486","post","type-post","status-publish","format-standard","hentry","category-phishing"],"_links":{"self":[{"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/posts\/486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/comments?post=486"}],"version-history":[{"count":1,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/posts\/486\/revisions"}],"predecessor-version":[{"id":490,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/posts\/486\/revisions\/490"}],"wp:attachment":[{"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/media?parent=486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/categories?post=486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pages.vassar.edu\/catchoftheday\/wp-json\/wp\/v2\/tags?post=486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}