WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Security Awareness – Current Phishing Campaign Leverages Fake Outlook Web App
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Security Awareness – Current Phishing Campaign Leverages Fake Outlook Web App

Author: Alec Davison

Created: Thursday, November 18, 2021 - 19:00

Categories: Cybersecurity

A new phishing scam is using the likeness of Microsoft Outlook Web App to steal credentials. Researchers at Mailguard observed a recent phishing campaign from an unknown group of cyber criminals seeking to gain access to user credentials. The email asks users to ‘validate your account’ by clicking on a nefarious link and entering your password. After clicking the link, victims are directed to a mimicked version of the Outlook Web App login page and asked to provide their username and password. After the victim submits their credentials, the threat actor collects them for later use, and the victim is met with an error saying “The password you entered isn’t correct. Try entering your correct password again.” Outlook Web App users should be aware of the features of this scam. The phish uses the displayed email address of ‘IT_Oprations [at] tech-centre [.] com’ and claims to be from the ‘Accounts’ department. The word ‘operations’ is spelled incorrectly, underscoring the fraudulent intent of the email. Members are encouraged to use this current theme in security awareness reminders. Likewise, this example is another reminder to always use caution when opening emails from outside an organization and to carefully scrutinize the sending email address and any links contained within the message. For more about this current campaign, including an image of the phishing email, visit Mailguard.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar