This content from the SAP Concur Community was machine translated for your convenience. SAP does not provide any guarantee regarding the correctness or completeness of this machine translated text. View original text custom.banner_survey_translated_text
User who recently started using Concur Expense received this email - I removed to "To" name for security with PII:
The subject line and email body are the same as what I've seen on posts about these emails, but when I hover over the link in the email body it reveals the original URL as going to bofa.com-onlinebanking.com - which is HIGHLY SUSPICIOUS
This appears to be a phishing email to me, but it has the user's full name in the To: and in the "Dear ....," so how would it get that information?
This content from the SAP Concur Community was machine translated for your convenience. SAP does not provide any guarantee regarding the correctness or completeness of this machine translated text. View original text custom.banner_survey_translated_text
Hello @USWsdymerski ,
I’m sure this is a suspicious email:
Sender domain
From: Concur Solutions <noreply@credit-transactions.com>
This is not an official SAP Concur domain.
Legitimate Concur emails usually come from domains such as:
This point alone is already a very strong red flag.
Most likely, a user’s address book has been compromised, which is why the attackers have access to all the contact information and can personalize the email.
BR,
cj
This content from the SAP Concur Community was machine translated for your convenience. SAP does not provide any guarantee regarding the correctness or completeness of this machine translated text. View original text custom.banner_survey_translated_text
Hi @USWsdymerski,
To piggyback on @cjmarimo's comment, always check the From address. The list of From addresses used by SAP Concur is here. Outstanding Credit Card Charge emails are usually Email Reminders, which come from EmailReminderService@concursolutiuons.com.
How they got that user's information, I couldn’t say. Phishermen often cast very wide nets, hoping to catch anything, and as SAP Concur grows, our users can become targets.
I’d suggest a few things:
Excellent sleuthing by examining the details of the URL!
Fun little story: Once or twice per year, our IT team intentionally sends fake phishing emails to see if we’re paying attention and using the Report Phishing tools appropriately. A few years ago, I received one of these emails and while I was examining the URL I accidentally clicked it. Thankfully, it was not really a phishing email, and no harm was done. Unfortunately, because I clicked the link, I was automatically enrolled in a mandatory cybersecurity training.
Thanks,