LSU is working with a federal agency to investigate a coordinated cyber phishing attack on student and faculty emails by hackers trying to gain access to direct deposit credentials, officials say.
Two weeks ago, LSU IT Security noticed an increase in phishing—hackers posing as real websites or financial institutions in an attempt to get victims to reveal login information. Microsoft, which became the host of LSU email addresses when the school switched last year from Gmail, noticed an uptick in the number of these attacks on all higher education accounts, says LSU IT Communications and Planning Officer Sheri Thompson.
University officials declined to specify which federal agency the school is partnering with to investigate the attack, but say LSU IT Security and school administrators are working to find the source.
“This attack more than likely involves a large cyber-criminal syndicate as these attacks are more widespread than just LSU,” Thompson says.
A “limited number” of students and faculty have clicked the links attached to the malicious emails, she says. Last Friday, LSU sent a mass email to students warning of these attacks and urging students to be wary of emails that do not look “quite right.”
“These guys are very talented,” says Stephenson National Center for Security Research Training Director Jeff Moulton, who teaches businesses how to handle phishing and hacking attempts. “If you’re not really looking for it—and this is what they’re gambling on—you’ll just click. And in reality you’re clicking into a malicious site.”
Moulton says attackers do not generally target universities. Large businesses are targeted frequently, and “a lot of people click.”
Users who receive suspicious emails should look to see if the browser has “https” before the address, he says, which means the address is secure. Also, users can copy the link from the email and put it into the address bar of another browser to avoid giving up their login information.
—Sam Karlin
