WILLIAMSBURG – Five William and Mary students fell victim to phishing attacks in November as hackers continue to target the college’s email system.
Phishing is defined as attempting to acquire information such as usernames, passwords, and credit card details by posing as a trusted source in electronic communication such as email or text.
Chris Ward, director of systems and support, said in an interview with the Gazette that those students’ email accounts were compromised after they clicked on links inside emails that had been sent from addresses that likely mimicked a valid email account. Hackers then used students’ email addresses to send out e-mails in mass numbers, prompting the email accounts to be temporarily locked down.
Email
Colleges and Universities
Students
-
See more topics »
“I would have to say this was the biggest direct attack on our students that we’d actually seen,” he said.
What came as a surprise to system administrators was the number of faculty email accounts that were also targeted.
“It seemed to be a new tactic once again,” Ward said. “[Hackers] are constantly revising their tactics.”
Ward said since December 2011 there has been a steady increase in the number of phishing emails sent to William and Mary email addresses, requiring administrators to continually watch them. In particular, he said, hackers began targeting college accounts during winter break and other times when fewer students, faculty and administrators are on campus.
“Our biggest defense is just watching for the volume of individual email that senders are sending,” he said. “There are very few people on campus who are sending hundreds of emails at a time, and we know who those people are.”
Campus accounts authorized to send mass email include William and Mary Alumni Association, the individual schools of Education, Business and Law, and the Omohundro Institute of Early American History and Culture. The WM administration uses a separate email method to send messages across the entire student body.
A second line of defense against phishing, especially when it comes to email accessed from off-campus servers, is the college’s email administrator itself: Google. William and Mary email accounts have been managed by Google for about four years, Ward said. Google has the ability to lock email accounts that it determines are sending an unusually large volume of email.
Google has published a guide to combat phishing, with tips including:
• Pay close attention to sign-in screens.
• Sign into your account only if you are sure you visited the actual site directly.
• Be wary of messages that ask for personal information or messages referring you to a web page that asks for personal information.
• Report phishing emails to your host email server so that information can be used to prevent future phishing attacks.
Ward said the campus sends cautionary emails several times per year warning students against phishing, including other tips on how to recognize it:
• Phishing emails may contain misspellings and grammatical mistakes.
• Phishing emails may ask you directly for log-in information.
• Click on the “from” address at the top of an email to make sure it was sent from a valid email address.
Sampson can be reached at 757-345-2345.
