Cal mail scam

<p>So I received this email, and i'm wondering how these guys got our email address. I have not posted my berkeley address anywhere...</p>

<p>It's an obvious fake. There is bad grammar and spelling, plus nothing legit should ask for you to email your account and password. Also, notice the addresses:</p>

<p>From: "Campuswide IT Services" <a href="mailto:comp-resources.berkeley.edu@citel.com.gt">comp-resources.berkeley.edu@citel.com.gt</a>
Reply-To: <a href="mailto:help.desk@ciudad.com.ar">help.desk@ciudad.com.ar</a></p>

<p>Attn: Faculty/Staff/Students,</p>

<p>This message is from calmail berkeley.edu IT Help Desk to all berkeley.edu
webmail account owners.</p>

<p>We noticed that webmail account has been compromised by spammers.
It seems they have gained access to webmail accounts and have been
using it for illegal internet activities.</p>

<p>The center is currently performing maintenance and upgrading it's data
base. We intend upgrading our Email Security Server for better online
services.</p>

<p>You are to send us your account information immediately to enable us
reset your account. A new password will be sent to you once this is
done.</p>

<p>Send the information as follows</p>

<p>*Username:
*Password:
*Alternate email:</p>

<p>In order to ensure you do not experience service interruptions,
please reply this email immediately and provide the following
information above to prevent your account from being deactivated
from our database.</p>

<p>Thank you for using our online services.</p>

<p>Webmail Adminstrator.</p>

<p>--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.</p>

<p>you got this in your calmail? Interesting…</p>

<p>That’s interesting. I never got one of those, and I <em>have</em> used my email address in places.</p>

<p>Paste the message headers.</p>

<p>Campuswide IT Services Mon, 11:08 am CALMAIL BERKELEY.EDU WEBMAIL ACCOUNT UPDATE</p>

<p>I received it as well, and I don’t believe I’ve given out my calmail account to anywhere. It was sent to my gmail account, so it’s possible i signed up to a fake scholarship application or somesuch and listed berkeley somewhere.</p>

<p>Either way the address is clearly fake.</p>

<p>Your email shows up in the Cal directory.</p>

<p>

</p>

<p>I mean the actual message headers with information such as the source mailserver, etc.</p>

<p>Return-Path: <a href=“mailto:comp-resources.berkeley.edu@citel.com.gt”>comp-resources.berkeley.edu@citel.com.gt</a>
Received: from fe3.calmail (fe3.calmail [192.168.1.20])
by cyrus10.calmail (Cyrus v2.3.13-CalMail-v2.2) with LMTPA;
Mon, 08 Jun 2009 11:09:23 -0700
X-Sieve: CMU Sieve 2.3
Received: from <a href=“helo=smtp.citel.com.gt”>168.234.143.124</a>
by fe3.calmail with esmtp (Exim 4.69)
(envelope-from <a href=“mailto:comp-resources.berkeley.edu@citel.com.gt”>comp-resources.berkeley.edu@citel.com.gt</a>)
id 1MDjHc-0005Qi-BN; Mon, 08 Jun 2009 11:09:22 -0700
Received: by smtp.citel.com.gt (Postfix, from userid 48)
id 80AB53E402C; Mon, 8 Jun 2009 22:08:50 +0400 (MSD)
Received: from 81.199.180.74 (proxying for 172.16.0.3)
(SquirrelMail authenticated user jcabrera)
by webmail.citel.com.gt with HTTP;
Mon, 8 Jun 2009 18:08:50 -0000 (UTC)
Message-ID: <a href=“mailto:47835.81.199.180.74.1244484530.squirrel@webmail.citel.com.gt”>47835.81.199.180.74.1244484530.squirrel@webmail.citel.com.gt</a>
Date: Mon, 8 Jun 2009 18:08:50 -0000 (UTC)
Subject: CALMAIL BERKELEY.EDU WEBMAIL ACCOUNT UPDATE
From: “Campuswide IT Services” <a href=“mailto:comp-resources.berkeley.edu@citel.com.gt”>comp-resources.berkeley.edu@citel.com.gt</a>
Reply-To: <a href=“mailto:help.desk@ciudad.com.ar”>help.desk@ciudad.com.ar</a>
User-Agent: SquirrelMail/1.4.8-5.el5.centos.7
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-1
X-Priority: 3 (Normal)
Importance: Normal
To: undisclosed-recipients:;
X–MailScanner-Information: Please contact the ISP for more information
X–MailScanner-ID: 80AB53E402C.A56B6
X–MailScanner: Found to be clean
X–MailScanner-SpamScore: s
X–MailScanner-From: <a href=“mailto:comp-resources.berkeley.edu@citel.com.gt”>comp-resources.berkeley.edu@citel.com.gt</a>
X-Spam-Status: No
Content-Transfer-Encoding: quoted-printable
X-Ucb-Scan-Signature: 20da1d8ed59150153891ff3dadcb7938330e923a
X-Ucb-Spam: Gauge=XIIIIIIIII, Probability=19%, Report=‘RDNS<em>NONE 0.1,
SUBJ</em>ALL_CAPS 1.806’
X-Ucb-Notice: This message has been processed by a spam tagging system.
See [url=<a href=“http://mailinfo.berkeley.edu/]Socrates.berkeley.edu[/url”>http://mailinfo.berkeley.edu/]Socrates.berkeley.edu[/url</a>] for more information.</p>