Previous phishing emails that IST deemed as impactful. Photo courtesy of chapman.edu.
In an effort to raise student awareness of fraudulent phishing emails, Chapman’s Information Systems and Technology (IST) department sent a simulated phishing test to students Oct. 12, said Information Security Officer George Viegas.
Phishing is the act of posing as a legitimate company in order to commit fraud against an account holder. The email was seemingly sent from IST — but used a different address than the one listed online — and told students to click on a link to change their passwords due to a security breach.
As of Oct. 18, software tracking revealed that 26 percent of students have clicked the fake phishing link in the email, Viegas said.
“That email was actually sent by my department,” Viegas said. “It was the first one that we have sent out to give a new anti-phishing training system. That email was sent out in an effort to educate our students. We did have some number of our students who clicked on that link and it took them to a training base that says ‘This is a Chapman University phishing test and we want you to beware of phishing, and here are the things to watch out for.’”
The department hopes that sending out this email will help determine how many students are vulnerable to these types of emails by cataloguing how many recipients access the link.
“We hope it will increase the awareness within our student body of how to recognize a phish. It will help them to distinguish what is a real email. And then we hope that by doing that over time, there will be less and less people clicking on a phish,” Viegas said.
The students who clicked on the link in the simulated phishing email were sent to a webpage that IST created explaining the rules to staying safe online, including deleting unwanted emails and forwarding suspicious emails to abuse@chapman.edu.
Some students felt that the fake phishing emails could potentially be counterproductive, perhaps leading students to dismiss emails that are truly malicious and assume that they were sent by the university.
“I think that’s interesting, but may give students the wrong idea. They may start clicking on more phishing emails thinking they are going to get to a secure link set up by the school and I do not think that is fair,” said Courtney Marshall, a sophomore news and documentary and theatre major. “But it also may teach students without them getting a virus like you typically would with a phishing email. Honestly, I don’t know whether I like it or not – but that’s very interesting.”
Viegas said that the phishes set up at Chapman in the past have included gathering students’ passwords and attempting to use them on a variety of different websites – including bank websites.
“If you use (a) username or password, chances are you’ll use the same password elsewhere,” Viegas said. “They either try to use ransomware or they try to get your ID and password so they can steal your identity.”
According to Viegas, the two main intentions behind phishing emails are to leave ransomware – which is a software that blocks access to a computer until the user pays a sum of money – on one’s computer to get money or to steal a user’s identity by acquiring their username and password through a web link.
In the last three months, the most impactful phishing emails designed to collect personal logins and passwords sent to the Chapman community that were reported to IST have been posted on a phish status webpage. Viegas said that the department only releases the most impactful or dangerous phishing emails for students to see.
“We actually do get many more. We don’t want to put too much information out there, but just the ones that are most impactful, the ones that we get the most reports about. The more amount of people that forward it, the more people are seeing it,” Viegas said. “Sometimes these guys won’t target all students. They’ll get a mail list from somebody and they may target 50 students or they may target a thousand students, so depending on how many people are reporting it, we get a feel for how impactful it is and we post it up there.”
According to the IST website, universities nationwide have noticed an increase in successful email-based phishing attacks.
“They come in bursts. There will be some weeks where you’ll suddenly get a burst of activity and there will be some weeks when they come slow, and then they come back again. It’s the same set of bad actors who are targeting all the .edu emails, and they go attack us and then go to a bunch of the other places, and then go back to Chapman,” Viegas said. “Sometimes they will send it to a large number of people, sometimes they will send it to a small number. The biggest I’ve seen is about 1,500 students getting an email at one time.”
