Skip to the content of the web site.

Spear Phishing -- Sample from 2008/01/22

Security >> Vulnerabilities (2008) >> 2008/04/03

On Tuesday, 22 January 2008 several users received spear phishing attacks inviting them to reveal their passwords as follows:

Date: Tue, 22 Jan 2008 05:40:42 +0100 (CET)
From: accountupgrade@uwaterloo.ca
Reply-To: account.upgrade@hotmail.co.uk
To: undisclosed-recipients:  ;
Subject: Verify Your Uwaterloo Account Now

Verify Your Uwaterloo Account Now

Dear Uwaterloo Account Owner,

  This message is from Uwaterloo messaging center to all
Uwaterloo email account owners. We are currently upgrading our
data base and e-mail account center. We are deleting all
Uwaterloo email account to create more space for new accounts.

  To prevent your account from closing you will have to update it
below so that we will know that it's a present used account.

***********************************************************
CONFIRM YOUR EMAIL IDENTITY BELOW
Email Username : ......... .....
EMAIL Password : ...............
Date of Birth : ................
Country or Territory : .........
***********************************************************

  Warning!!! Account owner that refuses to update his or her
account within Seven days of receiving this warning will lose his
or her account permanently.

Thank you for using Uwaterloo!
Warning Code:VX2G99AAJ

Thanks,
Uwaterloo Team
Uwaterloo.ca BETA
It should be clear that this is a hoax and not mail from a "Uwaterloo BETA Team" at the University of Waterloo:

Finally, if you have any questions/concerns or need help please let us know.

I am, Reg Quinton, Senior Technologist, Security (IST)
+1 519 888-4567x36070