Information security simulates Workday phishing email

The information security department recently ran a simulated campaign on email phishing. 

The simulation email read: "Subject: Action Required: Update Your Information in ADP by Monday, March 28, 2022". 

picture disc.

Warning signs of this phish email:

  • The sender was workday@corpoutlook[.]com. The legitimate email for Nebraska Medicine Workday is nebraskamed@workday[.]com. Although Workday is a Nebraska Medicine system, the phishing test was sent to all UNMC and Nebraska Medicine employees.
  • The URL link was workday.corpoutlook.com. It has nothing about Nebraska Medicine or UNMC in the sender or links.
  • The wording is off. It asks for the information "by the close of business." It's also contradictory, asking: "Do you have information you need to change" with a follow up that failure "will result in lapse of benefits." Malicious actors like to use a sense of urgency to trick users.
  • The email's appearance also is off, using a variety of colors and odd places for capitalization.

Information security asks that people use the "report suspicious" or "report phish" button to report any suspicious emails, even ones that may be part of a simulated campaign. More information on how to report phishing attempts is online here.

Malicious actors are increasingly sophisticated with their phishing emails. The actors can copy and paste signatures, logos, branding and use good grammar and spelling. Information about sites that Nebraska Medicine and UNMC use, such as Workday, can be public knowledge.

There also is an increased threat of compromised business accounts, or when a legitimate email account is compromised. This can be an email account that someone communicates with often and assumes is safe. If an email was not expected or seems "phishy," report the issue to information security.

Information security advises that it’s more important than ever to stay vigilant. To see recent real phishing emails that have impacted med center users, visit this online dashboard.