Showing posts with label phishing scams. Show all posts

Fake Jobs Offered via Zoom and Text Message

by in , , , , , , , , ,

Have you received a job offer via text from a "Rosa at SLD"? 

With a follow-up interview on Zoom?




CSUCI has seen an increase in job scams recently targeting our student population via text to their personal smartphone.

Here are some ways to spot these employment scams:
  • If it sounds too good to be true, it probably is.
  • Do your research, look online, and reach out to infosec@csuci.edu if you have any questions or concerns.
  • Most jobs require a resume, an interview, a background check, and a job application.
  • Asking you to buy a gift card to iTunes or any other service is a sign the offer is a scam.
  • Do not share your information until you have verified the possible employer as being legitimate.

Think you can spot a Phishing email? Take the Phishing quiz from Google https://phishingquiz.withgoogle.com

For on-campus jobs, please visit the Dolphin CareerLink:
https://www.csuci.edu/careerdevelopment/services/dolphin-careerlink.htm

For more information or questions about Information Security, contact CSUCI's Information Security Team at infosec@csuci.edu or visit https://www.csuci.edu/its/security/.

Beware of Coronavirus (COVID-19) Phishing Scams

by in , , , , , , , , , , ,

Most of us have seen and read in the news about the Coronavirus outbreak, currently known as SARS-CoV-2 or Coronavirus Disease 2019 (COVID-19). We wanted to remind you that during media intense events like this, cyber attackers take advantage of this opportunity and attempt to scam you or launch phishing attacks that attempt to get you to click on malicious links or open infected email attachments. Here are some of the most common indicators that the phone call or email you received is most likely a scam or attack (additional information on identifying scam phone calls and emails may be found at the Federal Trade Commission Consumer Information website).
  • Any messages that communicates a tremendous sense of urgency. The bad guys are trying to rush you into making a mistake.
  • Any message that pressures you into bypassing or ignoring our security policies and procedures.
  • Any message that promotes miracle cures, such as vaccines or medicine that will protect you. If it sounds too good to be true, it probably is.
  • Be very suspicious of any phone call or message that pretends to be an official or government organization urging you to take immediate action. 

For the latest updates consider visiting the World Health Organization website on Health and Disease Control, the Center for Disease Control website, or our own CSUCI Coronavirus (COVID-19) Information website. Please keep in mind Coronavirus scams and attacks can happen at work or at home, via email, text messaging or even over the phone. Don’t fall victim to bad guys playing on your emotions. 

If you feel you have received a phishing attack at work, simply delete the message or if you have concerns report it to your information security team.

Information Resources: 

Cyber Security Awareness Fair Coming to CI This Week!

by in , , , , , , , , , , , , , , , , , ,

Dear Campus Community,

In celebration of National Cyber Security Awareness Month (NCSAM) 2019, CSU Channel Islands Information Security is hosting a Cyber Security Awareness Fair on Tuesday, October 29th and Thursday, October 31st, 2019 and you are invited! Come join us for a two-day event that will provide insights from security professionals on the latest cyber threats and landscape, and the opportunity to collaborate across the university.

The Cyber Security Awareness Fair will take place on the main Camarillo campus at the Broome Library in rooms 1310 and 1320 from 9:00 AM - 5:00 PM on each day and will include a pizza lunch on both days until the food runs out.

This is a free event that is open to the entire CI campus community!

Please share this information with your friends and we hope to see you there!

Agenda

Tuesday 10/29/2019

09:30 AM - 10:30 AM Cybersecurity Education at CI
11:00 AM - 12:00 PM Nation State Attacks: You are a Target!
12:00 PM - 01:00 PM Scams Targeting CI Students
01:00 PM - 02:30 PM Diversity in Cybersecurity Panel
02:30 PM - 03:30 PM Securing your Home Router
03:30 PM - 04:30 PM Multi-Factor Authentication is Coming…
04:30 PM - 05:30 PM CI Cyber Security Club

Thursday 10/31/2019

09:00 AM - 10:00 AM How Secure is the Internet: Developing Secure Elliptical Curve Cryptography
10:00 AM - 11:00 AM Using a Raspberry Pi for Home Security
11:30 AM - 12:30 PM Cyber Security Jeopardy
12:30 PM - 01:30 PM The Cyber Threat Landscape and You…
01:30 PM - 02:30 PM The DARK Web…




Phishing Alert - 8/28/2019

by Anonymous in ,

Dear Campus Community:

We have seen recent activity targeting students’ financial aid refunds through phishing emails. We have provided an example of a financial aid phishing attempt below. The email attempts to lure students into logging into a fake University web portal, similar to myCI, for the purpose of accessing financial aid information. The attackers are able to use student login information provided through this web portal to access the student’s account and change the student’s direct deposit information. As a result, financial aid funds can be rerouted to a bank account controlled by the attacker. Therefore, the University has temporarily disabled all direct deposit bank information from student accounts. Students who anticipate receiving a refund will be mailed a check to the mailing address on file.

If you have clicked or responded to a phishing attempt, we recommend that you contact your financial institution about any possible fraudulent activity on your accounts and contact the Solution Center at solutioncenter@csuci.edu or 805-437-8552 to assist you with initiating a virus/malware scan.

CSUCI data has not been breached; this was a phishing campaign targeting student financial aid. Any information about financial aid and student refunds will come from an official University email account (sbs@csuci.edu / financial.aid@csuci.edu / financial.aid-global@csuci.edu) and no other email address.

As a precaution, Information Technology Services (ITS) has deleted the phishing email from all student inboxes and reset the passwords of all students who received this phishing email to ensure no malicious activity is actively in progress. If you need to reset your password, you can reset it using the Forgot Password service.

If you have any questions regarding this issue, please contact the ITS Solution Center at solutioncenter@csuci.edu or 805-437-8552, or Information Security staff at infosec@csuci.edu.

Please note, no member of ITS or of CSUCI will ever initiate contact with you for your ID, password or any other personal information either in an email, over the phone, and especially in an anonymous form. Only with your continued awareness and ongoing vigilance will we be able to keep your CSUCI data properly secured. If you receive an email which you suspect may be an attempt to phish for your personal or financial information, please contact Information Security at infosec@csuci.edu.

For more information on phishing, please visit the ITS Security website.

Phishing protection and external emails

by Anonymous in , ,

As email phishing attempts become more sophisticated, CSUCI is taking additional steps to help protect its users.

On Friday, March 15, 2019, Information Technology Services (ITS) will deploy a new feature that will make emails to University employees from external senders more easily recognizable. A caution message will be added to the body of all incoming external messages. The message in the body of the email will read:

“CAUTION: This email originated from outside of CSUCI. Do not click links or open attachments unless you validate the sender and know the content is safe. Please forward this email to infosec@csuci.edu if you believe this email is suspicious. For more information on how to detect Phishing scams, please visit https://www.csuci.edu/its/security/phishing.htm."

Be wary of any emails that include the above message. An email that includes the above warning is not necessarily malicious; however, it’s a reminder for you that the message originated outside of CSUCI.

The addition of this warning message is part of our ongoing cybersecurity initiative to combat spam and phishing emails, as well as helping you to avoid unnecessary delays in accessing your emails or computers due to phishing emails or viruses.


For more information contact the Information Security Team at infosec@csuci.edu.

Don't be a victim of identity tax theft! The IRS is helping to protect false tax claims.

by in , , , , , , , , , ,

One of the hot identity theft scams is submission of false tax returns in order to receive unearned or earned refunds. The IRS has a process to try and detect these false returns. If they suspect a false return they will mail a letter to the address the taxpayer listed in their previous year return. The IRS letter directs the taxpayer to visit an IRS site to verify the tax return submitted. Legitimate letters should direct taxpayers to idverify.irs.gov. More details are contained in this link:http://www.irs.gov/uac/Newsroom/Taxpayers-Receiving-Identity-Verification-Letter-Should-Use-IDVerifyirsgov.

The IRS also has a great website page detailing active tax scams: http://www.irs.gov/uac/Tax-Scams-Consumer-Alerts.

If taxpayers suspect they are a victim of tax fraud/identity theft, they should contact the Treasury Inspector General for Tax Administration at 1-800-366-4484 or via the web at:http://www.treasury.gov/tigta/contact_report_scam.shtml

Taxpayers can forward scam emails to phishing@irs.gov.

Fake Dropbox login page nabs credentials, is hosted on Dropbox

by in , , , , , , , ,

An email with the subject “important” tells recipients that they must sign into Dropbox in order to view a document too big to be sent via regular email, but clicking on the link included in the message brings people to a fake Dropbox login page that is actually hosted on Dropbox. 

Link to the rest of this SC Magazine article to find out more about this new scam.

Computer Security and You.

by in , , , , , , , , , , ,

Scammers, hackers, and identity thieves are looking to steal your personal information – and your money. But there are steps you can take to protect yourself, like keeping your computer software up-to-date and giving out your personal information only when you have a good reason.


Visit our friends at OnGuardOnline.gov and see what you can do to better protect yourself and your personal information.

Ransomware Infections on the Rise.

by in , , , , , , , , , , ,

In a recent news release by US-CERT, the United States Computer Emergency Readiness Team, US-CERT stated they are aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker, a new variant of ransomware, restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files.  As of this time the primary means of infection appears to be phishing emails containing malicious attachments.

Everyone who makes use of computer systems, including email, should be on guard for these types of malware infection attempts.  In many cases the email will appear to be legitimate and harmless but you need to ask yourself if you were expecting this communication, and if not, contact the sender to make sure it's legitimate.

To help mitigate any loss of data should you fall victim to this infection, you should take regular backups of your system and store your important files onto your file server which is backed up regularly.

To get more information about CryptoLocker, follow this link to the US_CERT website and think before you click!

October is National Cyber Security Awareness Month (NCSAM)!

by in , , , , , , , , , , , ,


Each and every one of us needs to do our part to make sure that our online lives are kept safe and secure. That's what National Cyber Security Awareness Month—observed in October —is all about!

Please take the time to review some of our resources available to help you become more aware of the current landscape for cyber-threats.




How to spot a phishing email.

by in , , , , , , , , , ,

With the recent flurry of phishing emails being received these days I thought I would post this quick guide to assist you in determining if the email you received may actually be a phishing email.

It could be a phishing email if:

  • There are misspelled words in the email or it contains poor grammar.
  • The message is asking for personally identifiable information (PII), such as credit card numbers, account numbers, passwords, PIN's or Social Security Number.
  • There are "threats" or alarming statements that create a sense of urgency.  For example: "Your account will be locked until we hear from you" or "We have noticed activity on your account from a foreign IP address".
  • The domain name in the message isn't the one you're used to seeing.  It's usually close to the real domain name but not exact.  For example:
    • Phishing Website:  www.regionsbanking.com
    • Real Website:  www.regions.com

Beware of Texting Hacks and Scams

by in , , , , , , , ,

You get a text message claiming your email account has been hacked. The message asks you to text back in order to reactivate your account. Has your account really been hacked, or is this a scam?  Read this short article to see what you should do if this happens to you.

Scan Your Computer

by in , , , , , , , ,


Once an anti-virus and/or anti-spyware package has been installed on your computer, you should scan your entire computer periodically. If your anti-virus package has the ability to automatically scan specific files or directories and prompt you at set intervals to perform complete scans, enable this feature.

What can I do to protect my computer?

  • Don't click on pop-up ads that advertise anti-virus or anti-spyware programs 
  • Use and regularly update firewalls, anti-virus, and anti-spyware programs 
  • Properly configure and patch operating systems, browsers, and other software programs. 
  • Turn off ActiveX and Scripting, or prompt for their use.
    For more information, please visit:

    Don't Get Caught by an IRS Phishing Scam!

    by in , , ,

    As we near "Tax Day 2013", many spamming and phishing groups are increasing their attempts to try and get at your personal information.  Please be sure to execute caution before responding to any email claiming to be from the IRS or any other government group and think before clicking that link.  

    IRS Releases the Dirty Dozen Tax Scams for 2013

    by in , , , , , ,

    View today's CI Information Security Awareness blog post to read about the IRS "Dirty Dozen" Tax Scams for 2013.

    March 2013 - secureCI Monthly Security Newsletter Now Available

    by in , , , ,

    secureCI, CI's monthly information security awareness newsletter is now available for viewing. Please follow this link to view the March issue of secureCI.

    If your browser questions a website's security, stop, think, and verify.

    by in , , , ,

    When visiting "https://" secure sites of banks and online shopping retailers, you may see onscreen warnings such as "There is a problem with the website's security certificate" or "Secure Connection Failed." Don't just click through to continue, or make a "one time" exception. The warning may only indicate that there is a harmless temporary problem with the site or with the network, but it can also mean that the site is bogus or has been compromised by hackers, and someone is listening in on your conversation with your bank or retailer.

    Be smart. Contact your bank or retailer by phone and find out if they know about a problem with their website or the network. Don't be the next victim of fraud.

    How to Spot a Phishing Scam

    by in , , , ,

    We've all received them, emails from a seemingly trusted source like a bank, delivery company or even your own place of employment, claiming there was some type of issue or another requiring you to offer up some personal information or to click on a link or button to help clear the issue up. If you receive an email similar to this DO NOT CLICK ON ANY LINK OR OFFER UP ANY INFORMATION! 


    This is a common form of security attack called a phishing or spear phishing scam.

    Groups attempting to steal personal information will often use e-mails that appear to originate from a trusted source to try and trick a user into entering valid credentials at a fake website. Typically the e-mail and the web site look like they are part of a bank or some other organization the user is doing business with.

    For example, it could be a phishing email if...
    • There are misspelled words in the e-mail or it contains poor grammar. 
    • The message is asking for personally identifiable information, such as credit card numbers, account numbers, passwords, PINs or Social Security Numbers. 
    • There are "threats" or alarming statements that create a sense of urgency. For example: "Your account will be locked until we hear from you" or "We have noticed activity on your account from a foreign IP address." 
    • The domain name in the message isn't the one you're used to seeing. It's usually close to the real domain name but not exact. For example: 
      • Phishing website: www.regionsbanking.com 
      • Real website: www.regions.com
    If you receive an email like this and you think it may be fraudulent, please report it immediately to the T&C Helpdesk at X8552, helpdesk@csuci.edu, or infosec@csuci.edu. Our technicians will assist you and instruct you on how to effectively remove it.

    Please remember... nobody from T&C will ever ask you for any personal information, including your password!

    Are you a hacker's target?

    by in , , , ,

    Hackers are constantly trying to gather information about you for a variety of reasons.  Find out what you can do to make it more difficult for them to success.  Watch this short video courtesy of SANS Securing the Human to learn who is targeting you, how you're being targeted and why.
    This video will be available through the end of December 2012.


    Don't click the "unsubscribe" link at the bottom of unsolicited emails

    by in , , , ,


    Spam filters do a good job of catching most unwanted e-mail, but some might still reach you.  Most spam is designed to get you to respond with your own email or to click a link to "unsubscribe".  When you respond or click the "unsubscribe" link, the sender can take your email address and add it to a SPAM database of active email addresses.  You might then start receiving large amounts of SPAM in your inbox.  To be on the safe side, don't respond or click the "unsubscribe" links on any unsolicited emails.