University of Iowa employees will no longer be able to access paychecks or other sensitive documents from home computers under a security measure designed to thwart online scams.
The change decided Monday means any function involving bank information, Social Security numbers and other sensitive information will be accessible only by computers on the university network.
University officials are trying to limit the impact of phishing attacks that have fooled dozens of employees into giving up their HawkID and login information. Cyber thieves have succeeded in stealing from two employees by changing their direct deposit information.
Chief information officer Steve Fleagle says the change will be “a big inconvenience for a lot of people.” But he says it’s necessary, at least temporarily, to try to “shut the bad guys right down.”
The University of Iowa says 74 more employees have been tricked into giving out personal information to online thieves who are trying to steal their paychecks.
University spokesman Joe Brennan said the employees fell for a so-called phishing attack that was similar to one last week that tricked 47 others.
He says in each case, they clicked on links and divulged login and password information used to access the university’s online services.
Brennan says those behind the scam are trying to change direct deposit information so that employee paychecks are routed to their bank accounts. He says they succeeded in stealing about $20,000 from two employees.
University police have launched an investigation. Meanwhile, the university is making a number of changes to block the emails and protect employee information.
