- Why Southern Title?
- Info Center
- Regulatory Compliance
A new phishing attack is using a number of tactics to trick unsuspecting users into handing over their login credentials. The email claims you have unread emails due to your cloud storage being full. It then gives you options to resolve the issue. Clicking on either link sends you to a phony login page for your service provider. And any information on this page will be sent directly to the scammers.
What makes this scam so sneaky? First, the phony log-in page not only looks official, but also functions like a real login page. Only passwords that meet real requirements are accepted. If an acceptable password is entered, you are redirected to the actual website of the service provider you just provided credentials for. Second, the email is sent from a no-reply address using the domain “servicedesk.com”. Most of us are used to seeing emails from support desks, which makes this sender feel legitimate. Third, the email itself bypasses security filters that you may have in place by using a combination of factors that makes your email security filters think the link is secure.
Don’t be fooled! Remember these tips:
Stop, Look, and Think.
Don't be fooled.
The KnowBe4 Security Team