Phishing Alert: Pitt Account Password Expiration Scam | Information Technology | University of Pittsburgh

Phishing Alert: Pitt Account Password Expiration Scam

Thursday, May 26, 2016 - 10:12


Computing Services and Systems Development (CSSD) is responding to a new email phishing scam that claims to be from the "Webmail administrator" and appears to originate from a email address. The email typically uses the Subject "IT Alert: Update your E-mail Account". It claims your password will expire in three days unless you click a link and provide your account details.

The following is a sample of the recent fraudulent email. If you receive this message (or any message similar to it), please report it as a phishing scam by forwarding the email message as an attachment to Detailed instructions on reporting scams are available at


Subject: IT Alert: Update your E-mail Account

Attn: Faculty/Staff/ Student

Your PITT Account Password will expire 3 days, please click <link removed> to validate and verify your e-mail account

This message is from Pitt Administrator Messaging Center to all Webmail Account Owners. Please follow instruction on this message and your account will be updated within 24hours. We sincerely apologize for this unusual problem.

Thank you for using our online services.

Webmail Administrator


The link in the phishing email directs readers to a malicious Web page that looks similar to the page shown below. The page attempts to collect youremail address, username, password, and domain.

Phishing Scam Login Page

CSSD strongly recommends that you do not reply to unsolicited emails or emails from unverifiable sources. Avoid clicking on links contained in such emails, as these may lead to sites that contain harmful software. If a link looks suspicious, you can hover over the link with your mouse to preview the URL without clicking on it.

In addition, CSSD recommends that all users install Symantec Endpoint Protection software and use the LiveUpdate feature to get the latest virus definitions. As a complement to Symantec Endpoint Protection, CSSD offers Malwarebytes Premium for individuals and departments at no cost. Students, faculty, and staff can download Malwarebytes and Symantec Endpoint Protection at no cost through the Software Download Service at My Pitt. Departments can submit a help request to obtain Malwarebytes for multiple machines.

Please contact the Technology Help Desk at 412-624-HELP [4357] if you have any questions regarding this announcement.