Many campus users are receiving e-mails claiming to come from an IT support group (sometimes even IMSS or the Help Desk) asking for the user's password and other private information. The messages may include a threat that the recipient's mailbox will be deleted unless a password is provided, to "verify" the account. Please be aware that this is a form of security attack known as “phishing” designed to fool users into giving their usernames and passwords to an attacker. Please do not reply to these e-mails or visit any websites they may refer to.
IMSS does not recommend providing usernames and passwords by e-mail, and IMSS will never ask users for their passwords by e-mail or by phone. If IMSS ever needs to ask users to log into a website, it would be a caltech.edu site and detailed information about this would be posted here on our website. Please note that sender address information on email is very easy to falsify, so do not rely on sender address alone as proof that a message is legitimate. To verify a website link, mouse over a URL in an email message, without clicking on it, to show additional information such as any discrepancies between the name of the URL and the site it really points to.