Phishing, most likely by overseas shysters, hooked staff members at the University of Michigan in two recent incidents when they provided passwords that allowed others to redirect pay deposits or obtain Social Security numbers, according to police.
The U-M Police Department sent out an alert today warning staff and students of the crimes. The department describes spear phishing, as e-mails made to look like official university messages targeting U-M students and staff.
“U-M has been experiencing several spear phishing attacks in which criminals sent email messages designed to trick recipients into revealing UMICH passwords,” the alert says. “In two recent incidents, staff provided passwords that enabled suspects to redirect employee pay deposits or obtain Social Security numbers, which could result in identity theft.”
The department pointed out the university’s official web log-in URL is https://weblogin.umich.edu. Phishing notes may use portions of that, but the log-in won’t be identical, according to investigators.
University users who receive a suspected phishing e-mail are asked to forward the entire original message with full headers displayed to abuse@umich.edu so it can be traced.
