Were you promised one million dollars from a Nigerian Prince only to lose your entire identity? It happens more than you think.
Approximately 12 to 15 email addresses were harvested daily from phishing scams in Western’s emails in the last month of the 2014-15 academic year, according to Jeffrey Gardiner, central information security officer at Western’s Information Technology Services.
This isn’t something new. Phishing scams have been around for decades. These days, they’ve become more focused and geared toward specific individuals.
“There’s a new kind of phishing that has emerged over the last couple of years called spear phishing,” Gardiner said. “Instead of just casting a wide net, they do a little bit of research about the person they’re targeting and they direct their phishing campaign not to the nebulous crowd but to you specifically.”
Scammers have gone so far as to replicate people’s email signature blocks, even showing awareness of who works for whom in an effort to trick their victims.
And with just a single password, it’s easy to gain access to things like human resource records, personal information and bank accounts. In some cases, emails and university credentials are even sold via consumer-to-consumer websites hailing from countries abroad.
Spammers and retailers are able to get away with it because it’s technically legal.
“The Internet does not fall within the sovereign domain of a particular nation state,” Gardiner said. “It’s truly global, so selling university credentials might be illegal in North America, but it doesn’t mean it’s illegal in China or Iran.”
There is an international treaty called the Convention on Cybercrime, but there are only 50 signatures. Even if there was a way to internationally regulate the internet, it would be heavily opposed — a reality America has been experiencing ever since the net neutrality debate.
At the university level, the same division exists between freedom of accessing information and protecting information.
“I think universities believe, because we support open access to information, we shouldn’t take steps to safeguard sensitive information,” Gardiner said. “I think that’s just a false perception. I don’t think that’s actually true.”
Currently Western does have safeguards against cyber attacks. There are firewalls and security incident event management tools, rules and regulations and online guides all currently in place to help combat cyber crimes. Though, the responsibility ultimately falls on the student.
Gardiner says younger generations are most likely to fall victim to phishing scams due to a false perception of security.
Fourth-year media, information and technoculture student Lydia Gibson agrees. She says students have a choice, but more often than not they choose to not exercise caution.
“I think students will knowingly use the same passwords for the same things,” Gibson said. “I honestly do believe that they aren’t aware of how secure they actually are on social media.”
Fourth-year computer science student Edmund Luong relates cybersecurity to practicing general security.
“It’s a risk like getting mugged,” Luong said. “It doesn’t happen often and you don’t think about it until it actually happens to you. Treat it like you would walking into a sketchy area, don’t make yourself a target and don’t walk around with valuables.”
