{"id":2041,"date":"2025-12-03T09:32:58","date_gmt":"2025-12-03T15:32:58","guid":{"rendered":"https:\/\/wp.uthscsa.edu\/phishbowl\/?p=2041"},"modified":"2025-12-03T09:32:58","modified_gmt":"2025-12-03T15:32:58","slug":"myut_health-ims-email-confirmation","status":"publish","type":"post","link":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/","title":{"rendered":"MyUT_Health-IMS Email Confirmation"},"content":{"rendered":"<p>This is a dangerous email, because it doesn&#8217;t have the usual red flags. The only red flag it had was it was sent outside of normal business hours. This tactic targets mobile users, making it easier to overlook other warning signs.<\/p>\n<p>There is an embedded image with a hidden malicious link in the body of the email.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2042\" src=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png\" alt=\"Screenshot of email\" width=\"983\" height=\"814\" srcset=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png 983w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS-483x400.png 483w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS-664x550.png 664w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS-768x636.png 768w\" sizes=\"auto, (max-width: 983px) 100vw, 983px\" \/><\/p>\n<p>The primary aim was to capture employees&#8217; login credentials and mobile phone numbers.<\/p>\n<p><strong>Attack Mechanism:<\/strong><br \/>\nUpon clicking the link in the image, users were directed to a fraudulent page prompting them to enter their login details and mobile number.<br \/>\nThe attackers then utilized the stolen credentials and phone number to initiate a Duo 2FA phone call, which unsuspecting users approved.<br \/>\nThis granted the attackers access to change account passwords and modify bank direct deposit information.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2043\" src=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2.png\" alt=\"Screenshot of malicious logon page.\" width=\"1600\" height=\"1200\" srcset=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2.png 1600w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2-533x400.png 533w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2-733x550.png 733w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2-768x576.png 768w, https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS2-1536x1152.png 1536w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a dangerous email, because it doesn&#8217;t have the usual red flags. The only red flag it had was it was sent outside of normal business hours. This tactic targets mobile users, making it easier to overlook other warning signs. There is an embedded image with a hidden malicious link in the body of [&hellip;]<\/p>\n","protected":false},"author":412,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2041","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>MyUT_Health-IMS Email Confirmation - Phish Bowl<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MyUT_Health-IMS Email Confirmation - Phish Bowl\" \/>\n<meta property=\"og:description\" content=\"This is a dangerous email, because it doesn&#8217;t have the usual red flags. The only red flag it had was it was sent outside of normal business hours. This tactic targets mobile users, making it easier to overlook other warning signs. There is an embedded image with a hidden malicious link in the body of [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/\" \/>\n<meta property=\"og:site_name\" content=\"Phish Bowl\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-03T15:32:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png\" \/>\n\t<meta property=\"og:image:width\" content=\"983\" \/>\n\t<meta property=\"og:image:height\" content=\"814\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"gerwitz\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"gerwitz\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/\"},\"author\":{\"name\":\"gerwitz\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\"},\"headline\":\"MyUT_Health-IMS Email Confirmation\",\"datePublished\":\"2025-12-03T15:32:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/\"},\"wordCount\":138,\"image\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2025\\\/12\\\/20251203MyUTHealthIMS.png\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/\",\"name\":\"MyUT_Health-IMS Email Confirmation - Phish Bowl\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2025\\\/12\\\/20251203MyUTHealthIMS.png\",\"datePublished\":\"2025-12-03T15:32:58+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#primaryimage\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2025\\\/12\\\/20251203MyUTHealthIMS.png\",\"contentUrl\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/wp-content\\\/uploads\\\/sites\\\/90\\\/2025\\\/12\\\/20251203MyUTHealthIMS.png\",\"width\":983,\"height\":814,\"caption\":\"Screenshot of email\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/uncategorized\\\/2041\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MyUT_Health-IMS Email Confirmation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#website\",\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/\",\"name\":\"Phish Bowl\",\"description\":\"Phish Bowl\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/#\\\/schema\\\/person\\\/2095530964cc8374433595be2eab7bde\",\"name\":\"gerwitz\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g\",\"caption\":\"gerwitz\"},\"url\":\"https:\\\/\\\/wp.uthscsa.edu\\\/phishbowl\\\/author\\\/gerwitz\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MyUT_Health-IMS Email Confirmation - Phish Bowl","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/","og_locale":"en_US","og_type":"article","og_title":"MyUT_Health-IMS Email Confirmation - Phish Bowl","og_description":"This is a dangerous email, because it doesn&#8217;t have the usual red flags. The only red flag it had was it was sent outside of normal business hours. This tactic targets mobile users, making it easier to overlook other warning signs. There is an embedded image with a hidden malicious link in the body of [&hellip;]","og_url":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/","og_site_name":"Phish Bowl","article_published_time":"2025-12-03T15:32:58+00:00","og_image":[{"width":983,"height":814,"url":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png","type":"image\/png"}],"author":"gerwitz","twitter_card":"summary_large_image","twitter_misc":{"Written by":"gerwitz","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#article","isPartOf":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/"},"author":{"name":"gerwitz","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde"},"headline":"MyUT_Health-IMS Email Confirmation","datePublished":"2025-12-03T15:32:58+00:00","mainEntityOfPage":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/"},"wordCount":138,"image":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#primaryimage"},"thumbnailUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/","name":"MyUT_Health-IMS Email Confirmation - Phish Bowl","isPartOf":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#primaryimage"},"image":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#primaryimage"},"thumbnailUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png","datePublished":"2025-12-03T15:32:58+00:00","author":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde"},"breadcrumb":{"@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#primaryimage","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png","contentUrl":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-content\/uploads\/sites\/90\/2025\/12\/20251203MyUTHealthIMS.png","width":983,"height":814,"caption":"Screenshot of email"},{"@type":"BreadcrumbList","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/uncategorized\/2041\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wp.uthscsa.edu\/phishbowl\/"},{"@type":"ListItem","position":2,"name":"MyUT_Health-IMS Email Confirmation"}]},{"@type":"WebSite","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#website","url":"https:\/\/wp.uthscsa.edu\/phishbowl\/","name":"Phish Bowl","description":"Phish Bowl","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wp.uthscsa.edu\/phishbowl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/wp.uthscsa.edu\/phishbowl\/#\/schema\/person\/2095530964cc8374433595be2eab7bde","name":"gerwitz","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1e6628f5d379deb64268f4658e72b047dd7498c88eed2f376a82d36778aa1632?s=96&d=mm&r=g","caption":"gerwitz"},"url":"https:\/\/wp.uthscsa.edu\/phishbowl\/author\/gerwitz\/"}]}},"_links":{"self":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts\/2041","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/users\/412"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/comments?post=2041"}],"version-history":[{"count":0,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/posts\/2041\/revisions"}],"wp:attachment":[{"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/media?parent=2041"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/categories?post=2041"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.uthscsa.edu\/phishbowl\/wp-json\/wp\/v2\/tags?post=2041"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}