[CircleCI Security Alert] Warning: Phishing attempt for login credentials

WordPress VIP offers CircleCI as an optional service for customers. Please reach out to VIP if you think you may have accidentally clicked a link.

Reposting the CircleCI Security Alert from Thursday, September 15, 2022

Yesterday evening (Sept 15), we (CircleCI) became aware of a phishing attempt for customers’ CircleCI and GitHub credentials. We have no reason to believe your organization has been specifically targeted or that your account has been compromised, but want our customers to be aware that there is an ongoing phishing attempt and to exercise due caution.
This is an example of the email impersonating CircleCI in an attempt to gain access to your account:

CircleCI will not require users to login to review any updates to Our Terms of Service. Additionally, these phishing attempts include links that send users to circle-ci[.]com, which is not owned by CircleCI. Any emails from CircleCI should only include links to circleci.com or its sub-domains. If you believe you or someone on your team may have accidentally clicked a link in this email, please immediately rotate your credentials for both GitHub and CircleCI, and audit your systems for any unauthorized activity.

If you need help or have any questions, please do not hesitate to reach out to our team.
To better building,

The Team at CircleCI

Please reach out to VIP if you think you may have accidentally clicked a link.