{"id":49741,"date":"2018-06-26T13:23:50","date_gmt":"2018-06-26T18:23:50","guid":{"rendered":"https:\/\/blog.cpanel.com\/?p=49741"},"modified":"2018-06-26T13:23:50","modified_gmt":"2018-06-26T18:23:50","slug":"how-to-spot-a-phishing-email","status":"publish","type":"post","link":"https:\/\/devel.www.cpanel.net\/blog\/products\/how-to-spot-a-phishing-email\/","title":{"rendered":"How to Spot a Phishing Email"},"content":{"rendered":"
A new well-designed phishing email has been aimed at cPanel users recently, and we want to help all of our users stay safe.<\/p>\n
Phishing, by definition, is the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication. Phishing emails can be sent to any email address. The most effective phishing emails make use of e-mail spoofing, where the ‘from’ address that your mail clients display seems to be valid. These emails will include a link that directs users to enter details at a fake website. This fake website will have the same look-and-feel as the legitimate one and are often nearly identical to the real one.<\/p>\n
With cPanel & WHM powering more than 1\/3 the websites on the internet, cPanel users are some of the easiest targets out there. We take steps to help end users more easily weed out some of the obvious offenders by using strict SPF records, but that doesn’t prevent all attacks. Education, reporting, and mitigation is key to preventing the effectiveness of these attacks.<\/p>\n
The first step if you think you’ve received a phishing email is to confirm it.<\/p>\n
An example of a very well designed phishing email is below.<\/p>\n
<\/a><\/p>\n Notice that the content has very few typos, but the ‘from’ address has an incorrectly capitalized ‘CPanel.’ If you were to click on the ‘Accept the new terms’ button, you would be taken to a legitimate-looking form that appeared to be a cPanel login page, but the URL didn’t have cPanel anywhere it in.<\/p>\n If you fell for the trick (as so many of us have), the first step is to change the password for the impacted account. If you have used that password anywhere else, change your password there, too. Then make a plan to sign up for a password manager and start making unique passwords for each account you have.<\/p>\n Phishing attacks…<\/p>\n If you spot a phishing email, report it! If you spot a phishing email that claims to be from cPanel or sends you to a cPanel login page, report it and then send that email to\u00a0cs@cpanel.net<\/a>\u00a0with the full headers. That way we can track it them as well.<\/p>\n","protected":false},"excerpt":{"rendered":" A new well-designed phishing email has been aimed at cPanel users recently, and we want to help all of our users stay safe. What is Phishing? Phishing, by definition, is the act of attempting to acquire information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity […]<\/p>\n","protected":false},"author":77,"featured_media":64981,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[49],"tags":[2101,2105,2109],"class_list":["post-49741","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-gdpr-email","tag-how-to-spot-a-fishing-email","tag-phishing"],"acf":[],"yoast_head":"\nOh, no! I put my credentials in there!<\/h2>\n
Lets recap<\/h1>\n
\n