Phishing attacks lead to email changes
Posted: Friday, July 25, 2014 11:08 pm
vanderbilthustler.com
On July 10, Vanderbilt email began adding an [External] tag in the subject line of emails originating from outside of the central Vanderbilt email system. According to a Vanderbilt University press release, the tag was the result of a change made by VUIT after several Vanderbilt colleagues divulged their usernames and passwords during a targeted phishing attack.
Phishing is the practice of using email to lure unsuspecting Internet users to illegitimate websites. These messages are designed to entice users to divulge passwords and financial or other personal information, or to introduce a virus into a computer or network.
The most recent attacks were particularly targeted, with some aimed at possibly high-earning individuals.
Though some may be experiencing difficulty sorting threaded conversations due to the change, Vanderbilt IT has published tips for managing emails now marked [External] here.
Though additional security measures are in process, VUIT urges campus users to remain vigilant and offers the following suggestions:
- No entity at Vanderbilt will ask for your credentials, including ePassword verification, via email. Any email requesting you to do so should be treated as a potential phishing attack.
- VUIT will never ask you to modify your inbox or adapt security measures via an email link. Any email requesting you to do so should be treated as a potential phishing attack.
- If you receive an email tagged [External], please exercise caution in dealing with its content. The [External] tag may have some inconsistencies, some of which have been addressed.
- Be aware that attacks can also come from Vanderbilt addresses that have been “spoofed” by phishers.
- If you receive an email, either from an external or internal contact that you suspect may be a phishing attempt, please notify the VUIT Help Desk.
Posted in
News,
Administration
on
Friday, July 25, 2014 11:08 pm.
