A phishing campaign is seen targeting multiple enterprise environments by sending emails, some from apparently compromised accounts, that use typical subject lines related to financial services such as, “Fraud Detection from Message Center”. The emails advise of suspicious activity related to the recipients bank account. The emails have a calendar invite file attached (.ics) that the recipient is asked to open. The invite contains a link to page on a Sharepoint.com site which claims to be information from Wells Fargo advising the recipient of new security measures being introduced. Clicking anywhere on that page finally directs the user to the actual phishing page which is hosted by Google. This Wells Fargo themed page provides fields in which to enter account details to login. After providing information, victims are redirected to an actual Wells Fargo login page.