Northern Arizona University officials are warning employees and students to beware of phishing scams targeting the university’s email accounts.
“This is an ongoing issue,” said University Information Security Officer Lanita Collette. “The pattern that we seem to see is there’s a spike at the beginning of the semester.”
This time, the scammers seem to have changed their approach.
“This year was a little bit unusual,” Collette said. “We saw this spike that seemed to coincide with the beginning of the holiday season.”
Phishing is a type of online scheme in which the scammers use fraudulent means to trick a person into revealing sensitive information, such as usernames and passwords. Often, scammers send what look like emails from legitimate senders to obtain the information they want.
It is a big problem for organizations like NAU, where more than 30,000 student, faculty and staff email accounts are active on the school’s servers. The university also has a growing number of alumni keeping their nau.edu email accounts after graduation.
“That definitely makes us a big target,” Collette said.
She has seen scammers try everything, from generic emails telling the victims their email account is full to emails instructing students to click on a link to get information about their educational grants. One scam even sent fraudulent emails to NAU employees that appeared to be related to their benefits enrollment.
“Some of them are targeted to the university,” Collette said. “We have had some where, if you click on the URL they’ve provided, it would actually take you to a log-in page that looks a lot like a legitimate log-in page here on campus.”
There are many ways scammers can use the information they get from a phishing scam, but Collette has found two of them to be the most common.
“One of the things we see them do most often is use your email account to send out more spam,” she said. “Let’s say they catch you with a phishing attempt. They take your credentials, and then they use them to send out spam to try to get people to buy stuff.”
Another common practice of scammers hit university campuses across the nation last year.
“When they got the person’s username and password, they went into our HR system, changed the bank account that (the victim’s) payroll was going into and diverted funds into a fraudulent account,” Collette said. “People need to be careful, because you can have direct financial loss.”
Collette said NAU’s information security team constantly has to adapt to phishing scammers’ ever-changing methods.
“We’re fighting back hard,” Collette said.
One way NAU is addressing the problem is through the Information Security Essential Training module created by NAU’s information security team and the overall IT security team. It provides examples of what bad URLs and phishing emails might look like.
The training is mandatory for all faculty and staff but is also available for anyone who wants to take it.
The university also sends out email reminders to raise awareness about ongoing phishing scams. Collette said awareness has helped to crack down on those scams.
“Because we’ve been training people a lot around campus, we now have it kind of crowd-sourced,” she said.
People who suspect they have received a phishing email in their nau.edu email account can report it to the phishing@nau.edu email account. The information security team will block emails from that sender and remove the phishing emails from NAU inboxes.
Collette expects the phishing emails to slow down as NAU’s winter break continues and pick up again when the spring semester begins. In the meantime, she offered a few tips to keep NAU students and employees safe from scammers.
“The single most important thing is, if (an email) asks you to actually give a password, then it’s bad,” Collette said. “There are times someone might be asked for their username as part of trying to assist them with something, but we would never ever ask for a password to be sent through email.”
Users should also avoid clicking on any links in an email asking for sensitive information and never enter that information on a website that does not have a lock symbol in the address bar indicating it is a secure website.
More tips and NAU’s Information Security Essential Training are available online at www.nau.edu/its/learn/InfoSecEssentials/. The NAU Help Desk can be reached by calling 523-1511 and the Student Technology Center can be reached at 523-9294.
