Tag Archives: Phishing

#Phishing: Beware new phishing email

Beware new phishing email with subject line “RE: Faculty and Staff Notice”. Don’t click link to “IT ADMINISTRATOR SERVICE”

Image 001

For more information on phishing please visit http://go.middlebury.edu/phish

Please submit and suspicious emails or phishing attempts to phishing@middlebury.edu.

 

Email Phishing Alert

To our campus community,

We need to make you aware of an on-going phishing email attack on campus.  If you see a message like the one shown below, delete it and don’t respond.   It you have already responded to this email and given information, contact the Helpdesk at 802-443-2200 and check out the link below explaining what to do next.

http://www.middlebury.edu/offices/technology/infosec/education/phishing

These phishing emails can appear legitimate, though they take you to a non-legitimate site or email address.  Remember that the Helpdesk will never ask for your username/password.

Here is an example of the most recent email you may have received:

“To All
We currently upgraded our Server to 50GB inbox space. Please log-in to your user account to validate E-space.
Your emails won’t be delivered by our server, unless email account is confirmed.
protecting your email account is our primary concern,
for account update
CLICK HERE
should you have any questions please contact the IT Helpdesk.

INSTITUTE OF EDUCATION.
Copyright (c)2016 ITS Help Desk”

Be Safe,

Lisa Terrier
Helpdesk Manager – Service Requests
Middlebury College
110 Storrs Ave – Davis Family Library
Middlebury, VT 05753

Improved Filtering of SPAM and Phishing Email

ITS has begun enabling new, proactive anti-spam and anti-phishing email filters intended to improve the filtering of unsolicited and unwanted messages, by leveraging external reputation-based lists of email servers that have been flagged for sending spam and/or malicious email.

We’ve had the new filters in “Tag” mode since October 2014, so we’re confident that they are accurate and we’ll be closely monitoring incoming mail queues during the days after the change. Still, there is a possibility that someone trying to sending you email will have their message blocked, if their email servers have been flagged for sending spam and/or malicious email. The sender, in such cases, will receive an email advising them that their message could not be delivered.

If you encounter such as scenario, (i.e. a legitimate sender is trying to email you, but the message is being blocked by Middlebury’s email servers), or you have noticed legitimate messages recently having been incorrectly tagged as [SPAM?], please contact the ITS Help Desk at helpdesk@middlebury.edu and we will help you identify and resolve the issue.

General questions about this change may be directed to infosec@middlebury.edu.

Phishing on campus!

Over the last week Middlebury experienced a dramatic increase in the number of successful phishing attacks that resulted in Middlebury user accounts being compromised. A phishing attack is the effort of maliciously using email or a web site to try to unwittingly gain information about another individual. These recent attacks resulted in two distinct outcomes. The first was that many of these accounts were leveraged to generate large amounts of spam. The second result from these compromised accounts is that the attackers attempted to connect to the Middlebury network with the exposed user’s credentials.

This past week many individuals across our campus received an email that looked similar to the one below:

————————————–

Message with “Middlebury” as the display name

 

Dear Member,

You Have 1 New Message

Click here to read

Sincerely,
Middlebury Webmail Service

————————————

The link in this message redirected people to copy of the Middlebury CAS Logon page. Two important things to know about email from Middlebury IT Services. First, Library and Information Services will never ask for your user credentials in an email. Second, if you find yourself on any web page that is asking for credentials, always verify the address in your web browser’s address bar, to ensure that the web page is where you really want to be. Just because a web page has the Middlebury logo does not mean it is always a Middlebury web site.

To protect against phishing remember the following rules:

  1. Never click on any links in a suspicious email.
  2. If you ever receive an unsolicited email  and you do not recognize the sender delete the message.
  3. If you receive an email that requests your credentials or asks you to click a link which takes you to a web site that requests your credentials, do not click the link but rather go to the web site through the institution home page, Middlebury.edu for example.
  4. If you suspect an email is fraudulent delete the message.
  5. If you ever have questions regarding phishing or the content of an email call the Helpdesk.

The Helpdesk will help you determine if the email is legitimate. Please do NOT click on any links in a suspect email message.

If you suspect that you may have recently provided your Middlebury credentials to a fraudulent web site or email address, you should immediately reset your password at go/activate and then contact the Helpdesk.

If you become aware that your Middlebury account has been disabled, you must contact the Helpdesk to resolve.

More information is available at the Middlebury College Information Security web site at go/infoSec or contact the InfoSec office at infosec@middlebury.edu.

 

Ian Burke

Network Security Administrator

Middlebury College

infosec@middlebury.edu