This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Spear phishing attack in progress - U.S. universities

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=3917
Last Updated: 2008-02-01 03:58:06 UTC - "We’ve had a few reports of Universities/Colleges being hit with some very targeted emails trying to get the userid and password of students. The email is usually along these lines:

Subject VERIFY YOUR xxxxxx EMAIL ACCOUNT NOW

Dear xxxxx Email Account Owner,

This message is from xxxxx messaging center to all xxxxx email account owners. We are currently upgrading our data base and e-mail account center. We are deleting all unused xxxxx email account to create more space for new accounts.
To prevent your account from closing you will have to update it below so that we will know that it's a present used account.
CONFIRM YOUR EMAIL IDENTITY BELOW
Email Username : ………. …..
EMAIL Password : …………….
Date of Birth : ……………..
Country or Territory : ……….
Warning!!! Account owner that refuses to update his or her account within Seven days of receiving this warning will lose his or her account permanently.
Thank you for using xxxxxx!
Warning Code:VX2G99AAJ

Thanks,

Xxxxx Team

The sender will be often be xxxxxteam @ isp used to send msg or uni address. The reply address will be external to the organization. In the sample we have it is usxxxxxxcountupgrade @ live.com. (where xxxxx is the domain name used by the institution, without the .edu). The message often passes through some SPAM filters due to the relatively low volume of messages. If you have some samples we’d be interested in a copy. Look for messages to multiple recipients and increased volume of internal email to one specific external address… educate your students."

:ph34r:
FYI…

- http://www.securityfocus.com/news/11504
2008-02-01 - "In an ongoing attack, students and faculty at nearly a dozen universities and colleges have been targeted by phishing e-mails since the middle of January. The e-mail messages masquerade as missives from each school's help desk, asking that the student confirm their username and password as well as requesting more personal information, including date of birth and country of origin… Schools targeted include Columbia University, Duke University, Princeton University, Purdue University, and the University of Notre Dame. The e-mail accounts of students and faculty that fall prey to the fraud are used, in most cases, to send out further spam as part of a lottery scam, Pearson and IT administrators stated. The attack may have already hit European schools earlier in the month, one university IT administrator stated on a security mailing list… Phishing attacks targeted at a specific subset of people, while fairly common in the corporate world and against banking customers, have not often been used against students. Princeton and other schools sent out warnings to their students and faculty about the attacks and stressed that users should never give out sensitive information or passwords to other people…"

.
FYI…

- http://preview.tinyurl.com/2xsbuw
2/29/08 (University of Arkansas) -"The UA has been the target of e-mail "phishing" scams three times this year and University Information Technology Services is warning students to take caution. Precautions recommended by UITS include to remember the university and UITS will -never- ask for students' passwords via e-mail; never respond to suspected phishing e-mails under any circumstances; never reveal personal and confidential information such as credit card numbers, Social Security numbers or user names and passwords; remember legitimate businesses would never seek personal information via e-mail; and contact the department in question if unsure if a message is real. The UA has been the target of phishing scams in mid-December, again in mid-February and most recently last week, said Scott Fendley, the head of computer security… "Almost every major university and college in the country has had at least one instance of this type of targeted phishing attack"…"

:ph34r: