I just saw this tweet from someone senior at her former employer about how she uploaded a reference letter to an official-looking site but again, no screenshot or URL referenced.
I just saw this tweet from someone senior at her former employer about how she uploaded a reference letter to an official-looking site but again, no screenshot or URL referenced.
This could be something as simple as "someone@harvard-faculty.org".
For the recipient, this is effectively indistinguishable from a legit address. Not just because people are unsophisticated, but because many orgs really do use this sort of ancillary domain for conducting real business.
I've seen Fortune 50 corps, hospitals, and banks make this mistake.
Even if Harvard does not, has not, and will not ever make this mistake, an outsider would not be surprised to see it.
But the senders were not at Harvard, so it's very likely that they did not do so. And they would not need to do so, for their purpose.
If that is so... so what? Plenty of organizations use different domains. Fidelity staff uses "frm.com"-- as an example-- while most customers know them as fidelity.com.
They've gotten pretty good at crafting domains this way.
I suspect it is quite easy to make it look like many people from an institution are in a thread and a passive participant is an email address from a 3rd party job portal.
*Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
Edit: You added
> *Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
after my reply. I’m not sure how it is relevant to your claim that “alumni are often allowed to keep their addresses”. In fact the question doesn’t make any sense to me; I’m not gonna accept an MIT job offer from an alum.mit.edu address (or more relevant to me, alumni.stanford.edu/alumni.princeton.edu), regardless of network culture.
Edit 2: Reread your question and realized you were implying that MIT "recently" allowed alumni to keep @mit.edu addresses. Well, you'll need to show some proof.
This approach to identifying phishing is ultimately insufficient.