Phishing emails sent via OVGU accounts
Fraudulent emails have been sent via compromised OVGU email accounts.
In the emails currently known, the attackers pose as the OVGU’s IT service. Under the subject line ‘Your inbox is full’, they claim that the inbox has exceeded a set storage limit and cannot receive any further messages. Recipients are then prompted via a link to supposedly check or update their mailbox.
This message does not originate from the OVGU IT Service.
We have already taken steps to secure the affected accounts and to prevent the messages from spreading further.
Indications that the message is fraudulent
The phishing email currently known exhibits the following characteristics, amongst others:
- The sender is displayed as ‘OVGU IT Service’, although the message was sent via a compromised personal OVGU account.
- It threatens to block or perform de-registration on the email account.
- The wording appears unusual, incorrect or machine-translated.
- Recipients are urged to open a link using phrases such as ‘Click here’.
- The link does not lead to an official OVGU login page.
- The footer contains incorrect or out-of-date contact details for the IT Service.
- The contact address given is The official contact address for the IT Service is .
- The telephone number provided also differs from the official contact details.
- The intranet link provided simply redirects to the general OVGU website and is implausible in this context.
What to do
- Do not open the link contained in the message.
- Do not enter any login details, passwords or verification codes there.
- Do not reply to the message.
- Mark the email as spam or phishing in your email programme.
- Report the message to the IT Service at
- Delete the email afterwards.
If you have already clicked on the link or entered your login details, please change your OVGU password immediately and contact the IT Service.
IT Services will never ask you by email to update your account via an unknown link or to enter your login details.