Phishing on campus
Posted: Wednesday, November 12, 2014 10:30 am
vanderbilthustler.com
This past weekend, the Vanderbilt community was notified of another phishing attack on campus. Phishing is the practice of using email messages to lure unsuspecting Internet users to illegitimate websites. These messages are designed to entice users to divulge passwords and financial or other personal information, or to introduce a virus into a computer or network.
At 4.53 a.m. on Nov. 8, a phishing email was sent from an internal Vanderbilt email account to approximately 16,000 Vanderbilt users, according to a university press release. The sender claimed that the email was a “Vanderbilt ITS Important Notification” in its subject line. The phishing email requested that recipients click on two links in sequence and provide email addresses, usernames and passwords.
Later that night, Vanderbilt University Information Technology (VUIT) sent out an email to the campus community alerting users about the attack. According to Salvador Ortega, Director of Security Operations for VUIT, the investigation into the weekend attack is currently ongoing. Ortega said that the phishing attack was primarily focused on the medical center.
This campus-wide email was not the first notification of phishing attacks this year. Earlier in the year, VUIT began adding an “[External]” tag in the subject line of emails originating from outside of the central Vanderbilt email system in order to combat phishing attacks.
Despite heightened attention to attacks this year, Ortega said that phishing is nothing new to the university.
“This is not the first time we are seeing it happen. Phishing attacks happen at Vanderbilt daily. It’s just this one had a large scope,” Ortega said in reference to the Nov. 8 attack.
But even large attacks happen with some regularity on Vanderbilt’s campus. Ortega said that the week preceding this weekend’s attack also had two other large ones. In addition, large-scale phishing attacks also took place this summer.
According to Ortega, VUIT is constantly adjusting their defenses for new types of attacks and adapting to the new methods that attackers have. He said that the user remains the first line of defense against such tactics.
“The number one (safety) measure is for people to be educated on what a phishing attack looks like. If they see it, they can report it or just delete it. It’s the user who they are after,” Ortega said.
Ortega said the most recent phishing attacks have been seasonal in nature. People are more at risk closer to the holidays, as well as at the beginning and end of months.
For more information on phishing or if you suspect that your identity has been compromised, you can visithttp://it.vanderbilt.edu/ or call the Vanderbilt IT Help Desk.
Posted in
News
on
Wednesday, November 12, 2014 10:30 am.
