On Friday, January 30, 2009, a memo went out to all KU faculty, staff, and students. It read a little something like this:
|
This is a reminder that KU will NEVER ask for your password via email. There are at least two widely circulating emails (phishing attacks) that claim your account will be deactivated if you do not send your username and password. One of these specifically claims to be from "Support Team, University of Kansas." It is not. Please DO NOT RESPOND to these messages. If you have responded to any of them you should change your password immediately and notify the KU IT Security Office by email to itsec@ku.edu or by phone at 785-864-9003 so that we can check your account for unauthorized use. If you have not changed your password since January 15 you will begin to see the regular password change reminder each time you log on with your KU Online ID beginning on February 1. The spring password change must be completed by March 1. Information Technology |
We talk a lot about phishing on this blog. Here's the thing, though: all of these scams are essentially the same. These messages are all wolves in sheep's clothing, but sometimes the wolves accessorize differently. They might wear black shoes instead of brown, they may put on different earrings, but the effect is still the same: they are bad guys trying to get good guys to part with their confidential information.
If we posted a blog entry every time a new phishing e-mail came out, we'd need to hire a full-time blogger just to keep up with the posts. So here are some iron-clad tips to help you avoid getting phished:
|
From: Kansas University Mail Admin [mailto:kansas.8@maillier.com] Sent: Tuesday, February 03, 2009 12:34 AM To: ""@localhost.cc.ku.edu Subject: Confirm Email Account |
Do you see the issues here? Let's point them out:
|
From: Kansas University Mail Admin [mailto:kansas.8@maillier.com] <--That's not what we call our mail admin, and furthermore that's not a domain we use. Sent: Tuesday, February 03, 2009 12:34 AM <--Our sysadmins work hard, but we don't make them send messages in the middle of the night. They need sleep too! To: ""@localhost.cc.ku.edu <--No. Just...no. This wasn't sent to you, unless your e-mail address is ""@localhost.cc.ku.edu, which it isn't. Subject: Confirm Email Account <--Again, trying to get you to act without thinking. |
We want to hear about it when someone attempts to phish your credentials. If you get a message that you suspect is fake, take the following steps:
Keep an eye on the Be SeKUre blog, our Twitter feed, and the IT Security Office website for updates and alerts.

Comments
Post new comment