Compromised Accounts and Phishing

Scammers use many different tactics when crafting their schemes, but one of their favorite methods is to use a compromised account to send phishing emails. If a scammer wants to target a particular organization, such as Kent State University, accessing and compromising an account at that organization will be very helpful to them. Scammers may be able to use compromised accounts to circumvent certain email security policies, gain your trust more easily, and even conduct very convincing impersonations. Read on to learn more about how scammers use compromised accounts in phishing attacks, and how to recognize emails sent from compromised accounts! 

Why Compromised Accounts?

Scammers like to use the approach of sending messages from a compromised account because it makes their scams appear more legitimate to recipients. It is more believable to the recipient if an email appears to be coming from an internal address at your organization. Often, people receive an email from a compromised account and immediately fall prey to the scammer because they see who sent the message and trust it without looking at it closer. 

When it comes to accounts that have been compromised, it is important to understand how the account was put into that position. Typically, when an account has been compromised by a scammer, it is because they have managed to find a way to access a person’s sensitive account details. Oftentimes, phishing attacks can lead to accounts being compromised. 

This is most often done through credential capture phishing attacks. This method of phishing often asks the recipient of the message to enter sensitive details into a platform easily accessible by the scammer, often some type of online form. Once scammers have this information, they can sign into the person’s account and send out messages throughout their organization. In some cases, this can be prevented by the extra security layer provided by Multi-Factor Authentication (MFA).

Recognizing Phishing from Compromised Accounts

Should you fully trust an email just because it's coming from a familiar address?
If you answered no, good job!

Fully Trusting any email you've received without carefully examining its contents is never a good idea. The reason scammers use compromised accounts is because they anticipate that you will have your guard down because you see an address from an organization you're familiar with.

A few questions to ask yourself when receiving an unexpected email from a familiar email address:
1. Does the message seem urgent?
2. Is there a sudden change in writing style?
3. Is the sender randomly requesting sensitive information or financial support?

After recognizing that the message was sent from a compromised account, report it to phish@kent.edu. Our team will take steps to secure the account and ensure that the scammer can no longer use it for their malicious purposes. 

Examples

This example is being sent from a compromised Kent State University account. Notice the request to download additional software. Be sure to read messages in their entirety to gather as many details as possible. Notice the information about “one of your courses”. If you are a student or do not otherwise teach a class at Kent State, this should be a red flag. This particular message was also impersonating a Kent State University employee in an attempt to appear more legitimate.



This is another example being sent from a compromised Kent State account. This time, it is a fraudulent job offer. If the contents of a job offer seem too good to be true, they usually are. This scammer is also requesting that you send information to an outside Gmail account owned by them. Scammers will do this to ensure that they can keep the information and continue to contact you in case the compromised account becomes secure again.