New phish trapping students and faculty on first day of spring semester

Even though this one has bad grammar in it (“your account have been flagged” [sic]), we’ve had reports that this phishing scam has trapped both UD faculty and UD students.

Here’s what this one looks like:

From: University of Delaware © [mailto:webmaster@UDel.Edu]
Sent: Sunday, February 03, 2013 1:54 PM
Subject: UDemail Service – Your UDemail Account has been Flagged.

Due to miss-match of your account details,
your account have been flagged.

Click here to Unflag

Copyright © 2005-2013, University of Delaware.

When you “Click here,” you get taken to a UD-branded website:

Click small version of image to see full image.

The scammers have done a good job of making a believable fake UD page–but notice that the URL is NOT a udel.edu address.

If you fell for this scam, change your UD password ASAP at the Network page. If you are unable to do so, contact the IT Support Center (Use the web form or call [302] 831-6000.)

Richard Gordon