%PDF-1.3 1 0 obj << /Type /Catalog /Outlines 2 0 R /Pages 3 0 R >> endobj 2 0 obj << /Type /Outlines /Count 0 >> endobj 3 0 obj << /Type /Pages /Kids [6 0 R ] /Count 1 /Resources << /ProcSet 4 0 R /Font << /F1 8 0 R /F2 9 0 R /F3 10 0 R /F4 11 0 R >> /XObject << /I1 28 0 R /I2 29 0 R >> >> /MediaBox [0.000 0.000 612.000 792.000] >> endobj 4 0 obj [/PDF /Text /ImageC ] endobj 5 0 obj << /Creator (DOMPDF) /CreationDate (D:20250719194026+00'00') /ModDate (D:20250719194026+00'00') /Title (Report 07-2025) >> endobj 6 0 obj << /Type /Page /Parent 3 0 R /Annots [ 12 0 R 14 0 R 16 0 R 18 0 R 20 0 R 22 0 R 24 0 R 26 0 R ] /Contents 7 0 R >> endobj 7 0 obj << /Length 4871 >> stream 0.702 0.800 0.816 rg 34.016 34.016 543.969 723.969 re f 1.000 1.000 1.000 rg 45.266 281.192 521.469 465.542 re f 0.773 0.773 0.773 RG 0.75 w 0 J [ ] 0 d 45.641 281.567 520.719 464.792 re S 0.773 0.773 0.773 rg 61.016 296.942 m 550.984 296.942 l 550.984 297.692 l 61.016 297.692 l f 0.200 0.200 0.200 rg BT 61.016 693.716 Td /F1 14.4 Tf [(REACTIVATE YOUR USERNAME BEFORE 1 APRIL)] TJ ET 0.400 0.400 0.400 rg BT 61.016 664.909 Td /F2 9.0 Tf [(Posted on )] TJ ET BT 104.045 664.909 Td /F3 9.0 Tf [(August 02,2021)] TJ ET BT 170.069 664.909 Td /F2 9.0 Tf [( by )] TJ ET BT 184.577 664.909 Td /F3 9.0 Tf [(IT Communications)] TJ ET 0.153 0.153 0.153 rg BT 61.016 637.420 Td /F4 9.0 Tf [(Network access \(usernames\) for staff will expire at the )] TJ ET BT 279.581 637.420 Td /F1 9.0 Tf [(end of March)] TJ ET BT 335.588 637.420 Td /F4 9.0 Tf [( unless youreactivate your username.)] TJ ET BT 61.016 617.431 Td /F4 9.0 Tf [(We suggest that you reactivate yours as soon as possible to ensure uninterrupted access to IT services \(internet, email, )] TJ ET BT 61.016 606.442 Td /F4 9.0 Tf [(SUN-e-HR etc.\). Keep in mind that the cost centre manager still has to approve your request before your username is )] TJ ET BT 61.016 595.453 Td /F4 9.0 Tf [(reactivated; allow sufficient time for this to be done to avoid disruption of your service.)] TJ ET BT 61.016 575.464 Td /F4 9.0 Tf [(You will receive an email from )] TJ ET 0.373 0.169 0.255 rg BT 183.047 575.464 Td /F4 9.0 Tf [(helpinfo@sun.ac.za)] TJ ET 0.373 0.169 0.255 RG 0.18 w 0 J [ ] 0 d 183.047 574.313 m 262.220 574.313 l S 0.153 0.153 0.153 rg BT 262.220 575.464 Td /F4 9.0 Tf [( indicating that your username \("engagement"\) will expire soon. Three )] TJ ET BT 61.016 564.475 Td /F4 9.0 Tf [(notifications will be sent before the end of March. Alternatively, you can go directly to the )] TJ ET 0.373 0.169 0.255 rg BT 415.184 564.475 Td /F1 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 415.184 563.045 m 465.701 563.045 l S 0.153 0.153 0.153 rg BT 465.701 564.475 Td /F4 9.0 Tf [( page.)] TJ ET BT 61.016 544.486 Td /F4 9.0 Tf [(Once logged into the)] TJ ET 0.373 0.169 0.255 rg BT 146.570 544.486 Td /F4 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 146.570 543.335 m 192.587 543.335 l S 0.153 0.153 0.153 rg BT 192.587 544.486 Td /F4 9.0 Tf [( page, you can select the services you want to reactivate. You areencouraged to read )] TJ ET BT 61.016 533.497 Td /F4 9.0 Tf [(the ECP \(Electronic Communication Policy\) before reactivating.)] TJ ET BT 61.016 513.508 Td /F4 9.0 Tf [(Choose the services \(network / email usernames and internet usernames\) you want to register for \(see images below\).)] TJ ET BT 61.016 493.519 Td /F4 9.0 Tf [()] TJ ET BT 61.016 473.530 Td /F4 9.0 Tf [(Reactivation of internet usernames is no longer necessary and can be ignored.)] TJ ET BT 61.016 453.541 Td /F4 9.0 Tf [(Make sure you select the correct cost points and if you're unsure ask your cost centre manager. Click )] TJ ET BT 465.899 453.541 Td /F2 9.0 Tf [(Accept and )] TJ ET BT 61.016 442.552 Td /F2 9.0 Tf [(Reactivate.)] TJ ET BT 61.016 422.563 Td /F2 9.0 Tf [()] TJ ET BT 63.518 422.563 Td /F4 9.0 Tf [(You will receive a notification stating that your request has been submitted, as well as a confirmation email.)] TJ ET BT 61.016 402.574 Td /F4 9.0 Tf [(The webpage will indicate that it will be activated as soon as it has been approved by the cost centre manager. When the )] TJ ET BT 61.016 391.585 Td /F4 9.0 Tf [(cost centre manager approves the reactivation request access will be extended to the end of March next year.)] TJ ET BT 61.016 371.596 Td /F4 9.0 Tf [(If you have completed these steps successfully and still receive emails from )] TJ ET 0.373 0.169 0.255 rg BT 364.631 371.596 Td /F4 9.0 Tf [(helpinfo@sun.ac.za)] TJ ET 0.18 w 0 J [ ] 0 d 364.631 370.445 m 443.804 370.445 l S 0.153 0.153 0.153 rg BT 443.804 371.596 Td /F4 9.0 Tf [( urging you to reactivate, )] TJ ET BT 61.016 360.607 Td /F4 9.0 Tf [(please go back to the )] TJ ET 0.373 0.169 0.255 rg BT 149.072 360.607 Td /F4 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 149.072 359.456 m 195.089 359.456 l S 0.153 0.153 0.153 rg BT 195.089 360.607 Td /F4 9.0 Tf [( page and make sure the appropriate boxes are checked: Your Network / Email )] TJ ET BT 61.016 349.618 Td /F4 9.0 Tf [(usernames Your Internet usernames)] TJ ET BT 61.016 329.629 Td /F4 9.0 Tf [(If you are still not able to reactivate, please raise a request at )] TJ ET 0.373 0.169 0.255 rg BT 308.642 329.629 Td /F4 9.0 Tf [(servicedesk.sun.ac.za)] TJ ET 0.18 w 0 J [ ] 0 d 308.642 328.478 m 397.175 328.478 l S 0.400 0.400 0.400 rg BT 61.016 311.140 Td /F2 9.0 Tf [(Posted in:Connectivity,E-mail,General,Internet,News,Notices | | With 0 comments)] TJ ET q 155.250 0 0 18.000 61.016 484.310 cm /I2 Do Q endstream endobj 8 0 obj << /Type /Font /Subtype /Type1 /Name /F1 /BaseFont /Helvetica-Bold /Encoding /WinAnsiEncoding >> endobj 9 0 obj << /Type /Font /Subtype /Type1 /Name /F2 /BaseFont /Helvetica-Oblique /Encoding /WinAnsiEncoding >> endobj 10 0 obj << /Type /Font /Subtype /Type1 /Name /F3 /BaseFont /Helvetica-BoldOblique /Encoding /WinAnsiEncoding >> endobj 11 0 obj << /Type /Font /Subtype /Type1 /Name /F4 /BaseFont /Helvetica /Encoding /WinAnsiEncoding >> endobj 12 0 obj << /Type /Annot /Subtype /Link /A 13 0 R /Border [0 0 0] /H /I /Rect [ 183.0467 574.6312 262.2197 583.7887 ] >> endobj 13 0 obj << /Type /Action /S /URI /URI (mailto:helpinfo@sun.ac.za) >> endobj 14 0 obj << /Type /Annot /Subtype /Link /A 15 0 R /Border [0 0 0] /H /I /Rect [ 415.1837 573.2659 415.1837 573.2659 ] >> endobj 15 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 16 0 obj << /Type /Annot /Subtype /Link /A 17 0 R /Border [0 0 0] /H /I /Rect [ 415.1837 563.6422 465.7007 572.7997 ] >> endobj 17 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 18 0 obj << /Type /Annot /Subtype /Link /A 19 0 R /Border [0 0 0] /H /I /Rect [ 146.5697 543.6532 192.5867 552.8107 ] >> endobj 19 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 20 0 obj << /Type /Annot /Subtype /Link /A 21 0 R /Border [0 0 0] /H /I /Rect [ 61.0157 484.3099 216.2657 502.3099 ] >> endobj 21 0 obj << /Type /Action /S /URI /URI (http://blogs.sun.ac.za/it/files/2020/02/Your-Network-Email-usernames.png) >> endobj 22 0 obj << /Type /Annot /Subtype /Link /A 23 0 R /Border [0 0 0] /H /I /Rect [ 364.6307 370.7632 443.8037 379.9207 ] >> endobj 23 0 obj << /Type /Action /S /URI /URI (mailto:helpinfo@sun.ac.za) >> endobj 24 0 obj << /Type /Annot /Subtype /Link /A 25 0 R /Border [0 0 0] /H /I /Rect [ 149.0717 359.7742 195.0887 368.9317 ] >> endobj 25 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 26 0 obj << /Type /Annot /Subtype /Link /A 27 0 R /Border [0 0 0] /H /I /Rect [ 308.6417 328.7962 397.1747 337.9537 ] >> endobj 27 0 obj << /Type /Action /S /URI /URI (https://servicedesk.sun.ac.za) >> endobj 28 0 obj << /Type /XObject /Subtype /Image /Width 207 /Height 24 /Filter /FlateDecode /DecodeParms << /Predictor 15 /Colors 1 /Columns 207 /BitsPerComponent 8>> /ColorSpace /DeviceGray /BitsPerComponent 8 /Length 55>> stream X 0 }nbr휿e~iO6?m~iBN endstream endobj 29 0 obj << /Type /XObject /Subtype /Image /Width 207 /Height 24 /SMask 28 0 R /Filter /FlateDecode /DecodeParms << /Predictor 15 /Colors 3 /Columns 207 /BitsPerComponent 8>> /ColorSpace /DeviceRGB /BitsPerComponent 8 /Length 1684>> stream hoHSk…CCҟ5)!4D?80Q3~X*12Dƾ(SU1aBm1naqv?E$(,5jHUϸL8v#PTbRCeŒDyS}vGϜN*hHkiURSU~qie)i0:5u|ؑRej4 Hs1S-Zk'+ˡFM!8?84`1%PsUEQHiY>epXx5#HlAN(>z:֋kZ"d]{vPjU$ LbW$!(z-a¨Y[ð* 3XGW9?8RTOo*\ qYJ(,5Z;]e`ڍuT7NgN'CaқVEF>?U-9;2E{rnzwٍMFMYܡr*m#.fPdrQH&#O ENKd,q2V27գ#^ɹ*d z0F|9?8j^InF. ={YIW2(]ZYCoKE^@ği]Ytuo-b{F'E@-YmTAFF)$ێk9q@SmiD!&_tESnO| .PBAIɰ*z (95h13j"> VQ_7AedH=K'F͒@ɓ;wh-6fUyJ˿.yԥ^uGOp?@'Qh zP9tBv,& :/`F`9ޖ پHh2ޭrH䅺.QH(ZLJڵg7%BH<f-,59! *d$ă$LIL\+oHLu[>6?ݥ#'U߿}~6m#d,Anw&f1UQ[꣧%0y7Igu̓W5Z,'8"/p:"/^EH5b z+ృK.HN_Xj B/H,Ս-g,Si7fW ?㕕_p *֋5Uօ&x$K^M*Z9%-aY)Xn n$ B٣毁r\:K`pT72 ;E!%T_>)e5(Oj7}bwq? AT!w(ަ;oS)䎼ڇkZ ma endstream endobj xref 0 30 0000000000 65535 f 0000000008 00000 n 0000000073 00000 n 0000000119 00000 n 0000000343 00000 n 0000000380 00000 n 0000000518 00000 n 0000000649 00000 n 0000005572 00000 n 0000005684 00000 n 0000005799 00000 n 0000005919 00000 n 0000006027 00000 n 0000006155 00000 n 0000006232 00000 n 0000006360 00000 n 0000006472 00000 n 0000006600 00000 n 0000006712 00000 n 0000006840 00000 n 0000006952 00000 n 0000007079 00000 n 0000007203 00000 n 0000007331 00000 n 0000007408 00000 n 0000007536 00000 n 0000007648 00000 n 0000007776 00000 n 0000007857 00000 n 0000008155 00000 n trailer << /Size 30 /Root 1 0 R /Info 5 0 R >> startxref 10097 %%EOF E-mail « Informasietegnologie
Language:
SEARCH
  • Recent Posts

  • Categories

  • Archives

E-mail

Phishing attack from compromised staff account with attached “Secure Message”

Wednesday, May 6th, 2020

With most students and personnel all working from home during the national lockdown, and with the reduced security (and watchfulness) of home computers and personnel/students in their home environment, and with many forced to use unfamiliar means of communication and collaboration like Teams, Zoom, Skype and Skype For Business, the environment is ripe for exploitation by phishers.

The following e-mail (with an infected attachment) is making its rounds at the moment from  a staff email.

If you get an email that look like the following do not open or respond to it. It is quite likely that the personnel doesn’t even know his account is compromised.

Please be careful when opening up attachments “sent” by colleagues especially if they are unannounced or the e-mail makes you feel a bit suspicious. Always trust your instincts.

“Sextortion” scams

Tuesday, April 28th, 2020

There has been a resurgence of “sextortion” phishing scams recently but with a slight twist.

“Extortion phishing” or “sextortion” is an aggressive form of a phishing attack that targets potential victims in an e-mail demanding bitcoin in exchange for a promise of non-disclosure of an alleged sexual offence.

The aim of these sextortion e-mails is clear – to force their intended victims to pay up for their silence, or the footage will be shared on social networks. Ultimately this is a typically insidious scam that could easily snare an unsuspecting user.

This variant however has an added twist, in that the phishing scammers are displaying a stolen password (from other websites) that their victims use, to grab their victim’s attention.

It is usually those other websites (e,g,. hotmail, Instagram, Paycity or Facebook) that hackers use to gain access to our data, so changing those passwords are very important.

As in the example below we received earlier this week:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Several students and personnel say that they have also received similar phishing e-mails, and that password that they had used were displayed in the subject line. They were all concerned that their network account was under attack.

If you receive such a mail, there is little danger to you UNLESS you

  1. respond to the sender
  2. still use that same password for other non-university accounts and use a variation of that password.

If it is an old password that they are displaying, then the danger to you is relatively small, but if you are still using it on a different website or application please change and update immediately.

[ARTICLE BY DAVID WILES]

Phishing emails, SMS and WhatApp messages offering payment relief during lock down

Wednesday, April 1st, 2020

A new potential threat has emerged as we enter the 2nd week of the national lock down and facing the beginning of the new month with bills  to be paid.

Phishers are already targeting the South African public with so-called COVID-19 phishing scams, attaching malware infected attachments and encouraging victims to click on a link to download “important information about the COVID-19 pandemic”.

However this week’s scam involves emails, SMS and WhatsApp messages being sent with information about “Payment Relief” from South African banks.

While it is true that most major South African banks are offering payment relief measures to their customers, phishing scammers have grasped this opportunity and adapted their tactics to send emails with content like the following:

“Dear Valued Customer,

“At ABSA Bank, we realise that this is a difficult time for our customers and businesses whose financial means are being negatively affected. After careful consideration and engagements with The Minister of Finance the, Hon. Tito Titus Mboweni, we are pleased to offer you, as a valued customer, a once-off access to a comprehensive relief programme. Please click on the following link to see if you qualify for payment relief.

VERIFY YOUR ACCOUNT

This is a once-off offer made to selected customers and will close at midnight on 2 April 2020.”

This is one such e-mail, but similar scams with forged identities from other South African banks, as well as Whatsapp and SMS messages will also surface. Note the specific deadline and the call to verify your account. Your bank won’t ever ask you to verify your account by email and certainly won’t give you a day to make such a decision. 

If you need to make use of a relief programme, rather contact your bank directly than reply to an online message. 

Here is a collection of the current verified details for payment relief from South Africa’s 4 major banks:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 [ARTICLE BY DAVID WILES]

Sending emails to large groups

Monday, March 2nd, 2020

Occasionally it is necessary to send emails to external students or other large groups of people who are not part of the sun domain. If you are currently using Outlook distribution lists we recommend that you switch to the much more user-friendly and functional Sympa mailing list management platform.

The reason for this is that Microsoft has started to limit the number of emails a sun email address can send to to 30 external email addresses per minute. Therefore, if you send to more recipients, Microsoft automatically blocks your account as their attempt to prevent spam. More detailed information on Microsoft’s policies regarding email limits, can be found on their website.

For many years the university has been using Sympa as mass mailing solution successfully. In fact, many of our staff and students use it to administer their lists. 

Sympa is a mailing list management (MLM) software and has its roots in the academic computing community in France. Its name, which is an acronym for Système de Multi-Postage Automatique (i.e. Automatic Mailing System), also means “nice” or “friendly” in French. We’re not sure exactly why the French decided to call their mailing list system “nice”, but we can confirm that it is “friendly” to use.

By using Sympa as a platform for your group emails, you will have better control over your emails and access to handy functions such as:

  • appoint one or several moderators;
  • manage subscriptions and unsubscriptions;
  • add a shared document web space at the subscribers’ disposal;
  • answer questions from subscribers and potential subscribers about the list
  • read the list archive;
  • search in the message archive;
  • review members of the list;

As you can see, Sympa offers much more functionality than your normal Outlook distribution list. Any staff member can use Sympa, simply go to https://sympa.sun.ac.za/sympa.
If you need any assistance in setting up your Sympa distribution list, please log a request for assistance on the ICT Partner Portal.

New warning banner for your email

Tuesday, February 4th, 2020

The nature of cyber-attacks is always evolving and Information Technology, with the help of staff and students, has to do everything within our power to try and prevent them.

In an attempt to tighten cyber security on campus, we will soon provide a new warning which can identify the origin of an email. By establishing the origin of email, it’s easier to protect against cyber security risks such as malware, spoofing and phishing. 

From now on, every time you receive email from outside campus a yellow banner will be displayed at the top of your email:

Click for a larger image

 

Click for a larger version

When staff or students receive a potentially dangerous email which seems to have been sent from a colleague with a sun.ac.za address, they will immediately be able to see that it is, in fact, not from their colleague, but from an address outside the university.

Just keep in mind that the banner does not indicate that the email is necessarily a security risk, but that the possibility exists and that you need to be extra careful when responding to it.

We will continuously assess the effectiveness of this decision and reconsider if necessary. For any additional enquiries, please send an email to help@sun.ac.za.

 

© 2013-2025 Disclaimer: The views and opinions expressed in this page are strictly those of the page author(s) and content contributor(s). The contents of this page have not been reviewed or approved by Stellenbosch University.