I think I was spearphished today

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    31,859
    77
    Camby area
    So I got an odd text early this am:

    IUH: You are now signed up w/ IUH Alerts. Reply HELP for help/txt.xxxxxxx.xxxxx. Reply STOP to cancel. Msg&Data rates may apply. MsgFreqPerAcctSetup. (removed potentially hostile link)


    Weird. I was already signed up.

    A couple hours later I get two more back to back.


    IUH: [my first name] has an appt Mon Dec 18 @ 1:00P w/Dr.[legit doc] [his legit address on a day he is there]. To cancel Reply NO2. Txt Help 4help.


    IUH: [my first name] has an appt Mon Dec 18 @ 1:00P w/Dr.[legit doc] [his legit address on a day he is there]. To cancel Reply NO. Txt Help 4help.

    Weird.

    At first I was freaked a bit because I googled him and its a psych and its a mental health/behavior studies lab. But since I have had a IUH account for years, and my account shows no upcoming appts in the system, I'm pretty sure its wrong. ( called one of his offices and she confirmed that he was in that lab on Mondays, but her office doesnt have access to the lab's appointments. So they are supposed to call me back tomorrow. (I called the lab number published on the web, not info in the text)


    Then I noticed the first appt alert. Computers dont make typos and then correct themselves 30 seconds later. :):

    Ive got a call into the doctor, but pretty sure I'm supposed to click the link in the first message and get infected by a virus or something. And since I didnt, the hacker decided to make me freak out about an appt I didnt make. But he made a mistake and then immediately sent the message again without the typo. Damn amateurs.

    Or I'm being committed to a mental institution on Monday and Nobody is admitting it. :):


    So be careful out there kids. The bad guys are getting sneaky.

    EDIT: Digging deeper, it may be a phishing test. I googled the domain in the first message, and it is registered to a parent company that specializes in cyber security. I think its a test to see if I fall for it. I didnt know my company was using another vendor for pen testing, but they just might be.
     
    Last edited:

    Phase2

    Grandmaster
    Rating - 100%
    6   0   0
    Dec 9, 2011
    7,014
    27
    That is possible. One info security technique is to test workers periodically to see if they fall for various scams. If so, either you individually or the entire company (if there are a lot of failures), get additional info security training.
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    31,859
    77
    Camby area
    Yeah, but I’m on the team that sets those up and I know nothing of this company. We use a different one.

    EDIT and we havent started testing via text, only email.
     
    Last edited:

    WebSnyper

    Time to make the chimichangas
    Rating - 100%
    58   0   0
    Jul 3, 2010
    15,615
    113
    127.0.0.1
    Yeah, but I’m on the team that sets those up and I know nothing of this company. We use a different one.

    EDIT and we havent started testing via text, only email.

    Agreed, I was going to say this is one of the first one's I have heard of using text. Most focus on email, to try and gain control of creds that may be hashed on a machine that's connected to the corporate network. This may be a new method or pen test to take advantage of the smart phone vector... interesting.
     

    T.Lex

    Grandmaster
    Rating - 100%
    15   0   0
    Mar 30, 2011
    25,859
    113
    Yeah, that is interesting.

    I know of a certain, rather large, IT department that instituted a separate spearphishing pen test program for their own IT department. It was a bit more polished than what went to the larger population of employees. It had a nominal "fail" rate - less than the employee population, and much less than the stats on the population at large, but still a non-zero number.

    But, part of me thinks this is more likely a failure of the text reminder system. Some bad data gets in there after a db conversion and things can get mucked up for awhile. As for the typo, someone has to type in the pre-merge message. :)
     

    WebSnyper

    Time to make the chimichangas
    Rating - 100%
    58   0   0
    Jul 3, 2010
    15,615
    113
    127.0.0.1
    Y
    But, part of me thinks this is more likely a failure of the text reminder system. Some bad data gets in there after a db conversion and things can get mucked up for awhile. As for the typo, someone has to type in the pre-merge message. :)

    Was wondering the same... might be some interesting HIPAA concerns there possibly depending on the extent of the problem.
     

    boogieman

    Expert
    Rating - 100%
    48   0   0
    Nov 14, 2009
    1,402
    63
    under your bed!!!
    I had an email a couple of days ago that was exactly the same type of thing. Mine is through Community though. They wanted me to confirm a scheduled appointment with a doctor I have had no contact with in 5 or 6 years. They wanted all my personal info and even had a confirmation number.
     

    Libertarian01

    Grandmaster
    Site Supporter
    Rating - 100%
    3   0   0
    Jan 12, 2009
    6,010
    113
    Fort Wayne
    ....Or I'm being committed to a mental institution on Monday and Nobody is admitting it. :):...



    You have friends here on INGO and we're here to help. Don't think of it as being "committed." Think of it rather as a friendly intervention with mandatory relaxation at a private and secluded facility for an indeterminate time. Think of all the fun you'll have.:stickpoke: :)
     

    OurDee

    nobody
    Trainer Supporter
    Rating - 100%
    25   0   0
    Sep 16, 2017
    8,068
    113
    Camby
    Pack comfortable slippers and an over sized robe. While in there, any time you find a magazine you like, carry it with you till you are finished with it.
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    31,859
    77
    Camby area


    You have friends here on INGO and we're here to help. Don't think of it as being "committed." Think of it rather as a friendly intervention with mandatory relaxation at a private and secluded facility for an indeterminate time. Think of all the fun you'll have.:stickpoke: :)

    I can still get on INGO, right? LOL
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    31,859
    77
    Camby area
    UPDATE: No spearphishing. Just a miscommunication. My doctor scheduled a test back in march 2 days after my last appt with him without telling me. Oh, and to make matters worse, right after doing that he moved out of state and left the practice. So now I get to go back in and start over with the new doc.

    But I'm glad I called. The lab they scheduled me at told me "We dont even do that kind of testing here." So I went ahead and cancelled the appointment. Talk about poor communication; He doesnt tell me he is ordering the test (he merely said it was an option) , and doesnt order the test at the correct facility. SMH.

    Why the system welcomed me after being signed up for several years is puzzling as well.
     

    JettaKnight

    Я з Україною
    Site Supporter
    Rating - 100%
    6   0   0
    Oct 13, 2010
    26,534
    113
    Fort Wayne
    "Txt Help 4help."

    The "4help" sets off my spidey senses. It's interesting that their phone database has your name.


    Reply All podcast had a good episode of the 800 number scams. It appears that this is an evolution of that.
     

    bwframe

    Loneranger
    Site Supporter
    Rating - 100%
    93   0   0
    Feb 11, 2008
    38,173
    113
    Btown Rural
    paranoiid-just-because-youre-paranoid-doesnt-mean-the-world-isnt-24922225.png
     
    Top Bottom