Phishing Alert: (Subject varies) Outstanding invoices (or) Monthly Invoice

Some U-M community members reported receiving this email. It is fraudulent or malicious. Do not respond, click any link in it, or provide personal information or money. See Phishing & Scams for more tips. If you need help, contact the ITS Service Center.

Date Sent: 
Tuesday, February 5, 2019

From line may be forged:

This scam often appears to come from someone the intended victim knows, such as a colleague, supervisor, or leader in their organization. The From and or Reply to lines are forged. Names and titles in many types of directories are publically viewable. Many organizations and units list important leaders on public web pages. The goal of this phish is to trick users into opening or downloading infected documents, or into entering their credentials in a phishing website.

Subject line examples seen include:

  • Outstanding invoices from [impersonated name]
  • month Invoice, [impersonate name]
  • Payment Advice for Outstanding Invoices [some date]
  • Your INVOICE

Body text examples seen include:

Hello,
Please find attached invoice summarising the jobs that are completed which we have not yet received a payment for.
Hope to hear from you soon.

---------

Thank you for your email.
As discussed please find attached the invoice for the insurance for this business.
Could you let me have payment within the next 7 days please.
Our invoice is attached.
THX, 

----------

Hello,
Can you send me a correct version of this invoice please?
You can download view using this link
Thanks for your continued trust! 

-----------

Please see attached and thanks!
Download DOC.