UMBC continues to receive phishing email campaigns from a malicious actor pretending to be from either Cisco or Corestaff. This phishing email has the goal of not only getting users personal information but also to try and get them to cash a fraudulent check. An example of the email can be seen below:
From: willliams rolase <rolasewillliams08@gmail.com> Date: Thu, Jul 9, 2020 at 2:22 AM Subject: WORK FROM HOME To: < @umbc.edu> Dear Student, We got your contact through your school database and I'm happy to inform you that our reputable company Cisco Systems Inc® is currently running a student empowerment program. This program is to help devoted and hardworking students secure a part time job which does not deter them from doing any other, you just need a few hours to do this weekly and with an attractive weekly wages. KINDLY EMAIL BACK WITH YOUR PERSONAL EMAIL ADDRESS IF INTERESTED IN THIS JOB POSITION. Best Regards, willliams rolase HR Manager/Consultant Cisco Systems Inc® |
If the user responds to the initial message the malicious actor will then respond asking the user for more personal information like name, address, city, state, Zip code, date of birth, gender, phone number, personal email and current job. Which can be seen in the below:
Dear Applicant, Thanks for getting back to us with your interest about the job position. ABOUT US: Cisco systems® is a privately held company within Allegis Group, the largest private talent management firm in the world. Our long-standing history and industry-leading position speak to our success in providing the IT staffing solutions, IT services and talent management insight required for our clients to actualize ROI and sustain a truly competitive advantage in a fast-changing market. We have established successful relationships with thousands of companies, government agencies and small entrepreneurial firms across all industries. COMMITMENT: Our commitment to meeting our customers’ and consultants’ expectations is the foundation for building trust in our business relationships. Simply put, we foster an environment that demands integrity and accountability for results. To ensure our clients and consultants know exactly what they can expect from us, we make it our mission to hire smart, honest and hardworking individuals who possess a great deal of pride in setting the bar high and keeping their word. JOB DESCRIPTION: Cisco systems® is seeking a production assistance to provide analysis and support for our clients production environment. This person will act as an intermediary between our suppliers and our agents in order to reduce their workload. As an intermediary/liaison, you'll be ordering production supplies, analyzing and making reports. This is a part time job that does not deter you from doing any other. You just need a few hours of your time to do this weekly and you can have your own part of the work completed at your leisure time in school or at home. HOURS OF WORK: The specific hours of work will vary each week but you will NOT be scheduled more than 6-8 hours per week. SALARY/WAGE: $400 Weekly. The successful candidate will need to be able to: -Provide Quality communication etiquette skills and good organizational skills. -Perform duties with accuracy, quality, and integrity. -Strong attention to detail, while under pressure with frequent interruptions. -Demonstrated ability to effectively coordinate multiple tasks and able to react to spontaneous changes in priorities. We will always email/text you guidelines and instructions to follow in getting your job done perfectly as soon as you start working. if you care to proceed with the job offer, kindly get back to us with the information listed below so we can process your information as to consider it valid to commence working with us. FULL NAME: PHYSICAL CONTACT ADDRESS (NOT PO BOX): CITY: STATE: ZIP CODE: D.O.B: GENDER: MOBILE (Must be able to receive text) : PERSONAL EMAIL: CURRENT JOB: We shall be contacting you as soon as we receive and validate this information. Regards, willliams rolase, HR Manager/Consultant Cisco Systems Inc®. |
If the user responds with their personal information the scammer will then inform the user that they have been accepted to the job, but due to Covid-19 they cannot do a one-on-one interview. They inform that a check will arrive with enough to cover your wage and your first task.
If you do receive this or a similar scam, please DO NOT respond any further. If you have provided any banking or financial information, please notify your bank or financial institution immediately. If you have been sent a check, you should not attempt to cash or deposit it. If you have deposited a check already, please contact your bank and tell them that it may be part of a scam.
Once you stop cooperating with the scam, you may receive a text message from the scammers. It may look something like:
Please be fully informed that this is a legitimate company and the HR department fully conducted a post survey before you were selected for this Employment.The company has put in maximum resources such as cost of shipment of check to you and profiling. Under the company Employee policy you are required to proceed by returning all the costs of shipment and profiling you for this position to the sum of $400. You are subjected to a lawsuit should you not return the company cost of shipment and profiling as you are responsible for the abrupt reject of this position. We will provide you details of the method of payment shortly. Please be aware that the company Attorney will in 24 hours profile you before the law court should you not comply with this terms of policy. I hope that you understand. |
This is part of the scam and seems to be intended to scare you. The real Cisco Systems doesn’t threaten legal action through text messaging and can afford to employ people who write grammatical sentences.
If you did receive this or any other email that you suspect is a scam, please do not click on any URL or reply. Either of those actions confirms to the sender that your email address is valid. Whether or not you responded to the scam, please forward the message (with the email headers) to security@umbc.edu. We will also keep track of any other information you submit about the scammers, such as phone numbers if you get a text message.
How do I forward full email headers?
https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970
To read more tips on how to spot and avoid phishing scams:
https://itsecurity.umbc.edu/critical/?id=93891
https://itsecurity.umbc.edu/critical/?id=93743
To read more articles published by DOIT visit: