Scam of the Month: Remote/Part-Time Intern for a Virtual Assistant | Office of Information Security (2024)

Newsletter

The Office of Information Security has observed a trend in which criminals advertise a job while impersonating someone from a university in Mexico. Impersonation is one of the most effective social engineering tactics scammers use, and it can be particularly enticing if offered employment.  

If you see a message like the one below, please do not interact with the sender and do not follow any special instructions. Simply report the email using the Phish Alert Button (PAB) in your Outlook interface. It is always best to be cautious and report anything remotely suspicious. Our team will analyze all submissions and return them to you if they are determined to be safe. Below, we dissect this phishing attempt to reveal its red flags. 

Scam of the Month: Remote/Part-Time Intern for a Virtual Assistant | Office of Information Security (1)
  1. The subject line is oddly worded. Typically, someone interns for an organization or department, not for a virtual assistant.
  2. The sender’s email address is from a university in Mexico. 
  3. The email body is empty.
  4. The only source for more information is an email attachment. Never open an attachment unless you know the contents of the file.

If you fell victim to a scam like this one, here are some steps you can take to secure your information

First, determine what information you revealed during the hiring process. If you provided your social security number, debit or credit card information, bank account information, or online login information before being hired, report it to the Federal Trade Commission at IdentityTheft.gov. They will give you advice tailored to your situation.  

If you opened a suspicious file, contact us at infosec@wustl.edu or 314-747-2955 

Avoid this and other scams by following our ten phishing safety tips and related guidance below. 

10 Phishing Safety Tips

  1. Don’t click. Instead of clicking on any link in a suspicious email, type in the URL or search wustl.edu for the relevant department or page. Even if a website and/or URL in an email looks real, criminals can mask its true destination. 
  2. Be skeptical of urgent requests. Phishing messages often make urgent requests or demands. When you detect a tone of urgency, slow down and verify the authenticity of the sender and the request by using official channels rather than the information provided by the sender.     
  3. Watch out for grammar, punctuation, and spelling mistakes. Phishing messages are often poorly written. Common hallmarks of phishing are incorrect spelling, improper punctuation, and poor grammar. If you receive an email with these problems, it may be a phishing attempt. Double-check the email address of the sender, dont follow any links, and verify the authenticity of the request using official channels.     
  4. Keep your information private. Never give out your passwords, credit card information, Social Security number, or other private information through email.     
  5. Pick up the phone. If you have any reason to think that a department or organization really needs to hear from you, call them to verify any request for personal or sensitive information. Emails that say “urgent!”, use pressure tactics, or prey on fear are especially suspect. Do an online search for a contact phone number or use the contact number published in the WUSTL directory in Workday.     
  6. Use secure websites and pay attention to security prompts. Always check if you are on a secure website before giving out private information. You can determine whether a website is secure by looking for the “https:” rather than just “http:” in the Web address bar or for the small lock icon in the Internet browser. If your browser cannot validate the authenticity of the websites security certificate, you will be prompted. This is frequently a telltale sign of fraud, and it would be a good time to pick up the phone or report a suspicious message.     
  7. Keep track of your data. Regularly log onto your online accounts and make sure that all your transactions are legitimate.
  8. Reset any account passwords that may have been compromised.     
  9. Know what’s happening. Visit the Office of Information Security Alerts page often.     
  10. Report it. If you are a victim of an email scam, report it to our office by using the Phish Alert Button (PAB). When you report a phishing attack, we will investigate it and, if necessary, remove other instances of the attack from our systems. Reporting the attack will help protect others and our institution.     

Additional Resources

Phishing | Office of Information Security | Washington University in St. Louis     
Phishing 101 | Office of Information Security | Washington University in St. Louis     

Protect Yourself from Social Engineering

Protect Yourself from Social Engineering

Scam of the Month: Remote/Part-Time Intern for a Virtual Assistant  | Office of Information Security (2024)
Top Articles
Bible Gateway passage: Genesis 22 - New King James Version
Bible Gateway passage: Genesis 4-8 - King James Version
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Things to do in Wichita Falls on weekends 12-15 September
Craigslist Pets Huntsville Alabama
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
What's the Difference Between Halal and Haram Meat & Food?
R/Skinwalker
Rugged Gentleman Barber Shop Martinsburg Wv
Jennifer Lenzini Leaving Ktiv
Justified - Streams, Episodenguide und News zur Serie
Epay. Medstarhealth.org
Olde Kegg Bar & Grill Portage Menu
Cubilabras
Half Inning In Which The Home Team Bats Crossword
Amazing Lash Bay Colony
Juego Friv Poki
Dirt Devil Ud70181 Parts Diagram
Truist Bank Open Saturday
Water Leaks in Your Car When It Rains? Common Causes & Fixes
What’s Closing at Disney World? A Complete Guide
New from Simply So Good - Cherry Apricot Slab Pie
Fungal Symbiote Terraria
modelo julia - PLAYBOARD
Poker News Views Gossip
Abby's Caribbean Cafe
Joanna Gaines Reveals Who Bought the 'Fixer Upper' Lake House and Her Favorite Features of the Milestone Project
Tri-State Dog Racing Results
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Twana Towne Ret

Last Updated:

Views: 5749

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Twana Towne Ret

Birthday: 1994-03-19

Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

Phone: +5958753152963

Job: National Specialist

Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.