You are on page 1of 4

Republic of the Philippines

NATIONAL POLICE
COMMISSION
PHILIPPINE NATIONAL POLICE, POLICE REGIONAL OFFICE 5
REGIONAL INFORMATION AND COMMUNICATIONS TECHNOLOGY MANAGEMENT DIVISION =
Camp BGen Simeon A Ola, Legazpi City

RICTMD-230124-001
MEMORANDUM

FOR See Distribution

FROM Chief, RICTMD

SUBJECT : Cybersecurity Advisory 1 PNP Mail Authentication Service

DATE January 24, 2023

1. Reference: Memorandum from AD, ITMS dated January 20, 2023 with
subject same as above.

2. This pertains to the fake PNP Mail Authentication Service phishing email
requesting sensitive information and attempting to persuade the recipient to click a
link that redirects to a phishing website.

3. In connection with the foregoing, the phishing email appears in the form of
a message from "info@pnp.gov.ph" requiring the recipient to authenticate their PES
account's mail box for validation due to "unusual activity" discovered on their victim's
account.

4. Upon verifying the legitimacy of the email, it was noticed that the email
account used by the threat actor "info@pnp.gov.ph" was a spoofed email address
and was originally sent by "richardsjoan471@gmail.com".

5. Email spoofing is a type of cyberattack that employs emails with forged


sender addresses. Because the recipient believes the alleged sender, they are more
likely to open the email, download an attachment , or click and open a malicious link.

6. In light of the foregoing, all PNP personnel are reminded to use caution
when accessing their respective PES accounts and are encouraged to practice basic
cybersecurity to avoid becoming a victim of a cyberattack .

7. Relatively, below are some characteristics of a phishing email:

a. Suspicious sender's email address;


b. Spelling and wrong grammar;
c. Generic greetings and signature;
d. Urgent call to active threats (false sense of urgency) ; and
e. Suspicious links and webs ites, or unexpected attachments.

8. In view of the foregoing, this division recommends the following tips on


how to avoid becoming a victim of a phishing attack:

"Life is Beautiful ...Ka/igtasan Nyo, Sagot Ko. Tulong-tulong Page 1 of 4


Tayo."
Ref. No.: RICTMD-230124-

a. Verify the sender's email address by checking the message's email


header:

1) For Chrome Browser:


a) Open the email you want to verify;
b) Next to Mark button, click More (three-dotted line) and choose
Show Source; and
c) Check the Return Path section to see the sender's original email
address. (Tab B)

2) For Windows Mail Client:


a) Open the email you want to verify ; and
b) Click the name of the sender on the "From" section of the email.

b. Hover the mouse on the link within the email without clicking to see if
the address matches the link that was typed in the message;
c. Never provide any personal information in response to an unsolicited
request;
d. Never provide passwords or OTPs over the phone or in response to an
unsolicited internet message;
e. Avoid downloading attachments or opening links from unknown
senders;
f. Change passwords on a regular basis; and
g. Keep system software and applications up to date.

9. You may visit https://pro5 .pnp .gov .ph or https://itms .pnp.gov.ph to


download learning materials regarding cybersecurity under the Computer Security
Tab. Also, for inquiries and concerns kindly contact the Regional Information and
Communications Technology Management Division (RICTMD) through email address
rictmd.pro5@pnp.gov.ph and RICTMD hotline number 09171096413 .

10. For widest dissemination.

RAYANV
Police Colone

Distribution:
R-Staff
P-Staff
PPOs/CPO
RMFB5
RHSU5
RSUs

Copy Furnished:
RD
Command Group

"Life is Beautiful ...Kaligtasan Nyo, Sagot Ko. Tulong-tulong Page 2


Ref. No.: RICTMD-230124-

:'<''1 lnfo@pnp.gov.ph <nchardSJOan47t@gmat l.com>

lo 1/10/2023. 10:48 AM
1.':>1··10 lnfo@pnp.gov.ph 0

u:>,1.'< • PNP Mall Authentication Service

I-
I image.png

We discovered unusual activity in your mail account


you are required to authenticate your mail box for necessary
validation.
kindly visit the login site for Authentication:

Login Authentication: httP-s:flmaii.J!!!1!:8 f!h


-----
hnp://pnpgovpt\.atwl!bpages..com/mat

Copyright © 2023 PNP Mail Authentication Service.


l.pnp.gov.ph.html

All Rights Reserved.

"Life is Beautiful ...Kaligtasan Nyo, Sagot Ko. Tulong-tulong Page 3


Ref. No.: RICTMD-230124-

Email Header

. .
Re<eived: f -.ill.pnp.fOY.ph (loc lhost [127.8.8.1})
%.. u·q·s· <;:: . ! ::"t!d)=- ; !.-(PST)
x-virus -sunned: visd-new •t uill.pnp.sov.ph
Auth ticltion-RMults: uill.pnp.sov.ph ( isd-new);
dki..p<lss (2&&&-bit key) he r.d •pail.cOII
Re< ived: f -.ll.pnp.cov.ph ((127.8.8.1))
by -.ill.pnp.gov.ph (-.lll.pnp.,ov.ph (127.8.8.1)) ( isd-new, port 1882•)
ith ESHTP id l<lPxOOpb)OlH for .p.ph>;
T , 18 l<ln 2923 18:.U:•t +e888 (PST)
Re< ived: f -.il -ot1-f6S.coocl .COII (unkno.n (289.85.216.65))
by uil.pnp.p.ph (Postfix) with ESHTPS id ..,.Z fofcCY
for • f;w,p.gov.ph>; Tu., 18 J<ln 2823 18:U:)9 +e888 {PST)
Re< ived: by 81il Ot1-f6S.f001l .COII with p id r6-2882818S6138'486eebee6141a9ld918S027868Aeotv.l2
for • .,lp.p.ph>; PQ , 89 )<lll 2823 18:U:39 -8886 (PST)

"Life is Beautiful ...Ka/igtasan Nyo, Sagot Ko. Tulong-tulong Page 4

You might also like