%PDF-1.3 1 0 obj << /Type /Catalog /Outlines 2 0 R /Pages 3 0 R >> endobj 2 0 obj << /Type /Outlines /Count 0 >> endobj 3 0 obj << /Type /Pages /Kids [6 0 R ] /Count 1 /Resources << /ProcSet 4 0 R /Font << /F1 8 0 R /F2 9 0 R /F3 10 0 R /F4 11 0 R >> >> /MediaBox [0.000 0.000 612.000 792.000] >> endobj 4 0 obj [/PDF /Text ] endobj 5 0 obj << /Creator (DOMPDF) /CreationDate (D:20250720104820+00'00') /ModDate (D:20250720104820+00'00') /Title (Report 07-2025) >> endobj 6 0 obj << /Type /Page /Parent 3 0 R /Annots [ 12 0 R 14 0 R 16 0 R 18 0 R ] /Contents 7 0 R >> endobj 7 0 obj << /Length 4030 >> stream 0.702 0.800 0.816 rg 34.016 34.016 543.969 723.969 re f 1.000 1.000 1.000 rg 45.266 317.192 521.469 429.542 re f 0.773 0.773 0.773 RG 0.75 w 0 J [ ] 0 d 45.641 317.567 520.719 428.792 re S 0.773 0.773 0.773 rg 61.016 332.942 m 550.984 332.942 l 550.984 333.692 l 61.016 333.692 l f 0.200 0.200 0.200 rg BT 61.016 693.716 Td /F1 14.4 Tf [(“PLEASE SUPPORT STIAS…” EMAIL CAUSES A MAIL STORM)] TJ ET 0.400 0.400 0.400 rg BT 61.016 664.909 Td /F2 9.0 Tf [(Posted on )] TJ ET BT 104.045 664.909 Td /F3 9.0 Tf [(January 01,1970)] TJ ET BT 173.588 664.909 Td /F2 9.0 Tf [( by )] TJ ET BT 188.096 664.909 Td /F3 9.0 Tf [(David Wiles)] TJ ET 0.153 0.153 0.153 rg BT 61.016 637.420 Td /F4 9.0 Tf [(There is no reason to be worried or concerned about a mail that is being circulated with the subject line starting with )] TJ ET BT 61.016 626.431 Td /F4 9.0 Tf [("PLEASE SUPPORT STIAS...")] TJ ET BT 61.016 606.442 Td /F4 9.0 Tf [(Although it is definitely spam)] TJ ET BT 175.064 606.442 Td /F2 9.0 Tf [( \(defined as unsolicited commercial e-mail\))] TJ ET BT 345.605 606.442 Td /F4 9.0 Tf [( it does not appear have any dangerous content )] TJ ET BT 61.016 595.453 Td /F4 9.0 Tf [(and was sent out by a university user to over 300 addresses one of which was the general IT Service Desk email address. )] TJ ET BT 61.016 584.464 Td /F4 9.0 Tf [(Because it was sent to the address which automatically logs service requests the account automatically emailed all the )] TJ ET BT 61.016 573.475 Td /F4 9.0 Tf [(recipients with "Cancellation" e-mails, who then replied, etc. This was no fault on the side of the IT Service desk as it is an )] TJ ET BT 61.016 562.486 Td /F4 9.0 Tf [(automatic process of the Jira logging software that IT uses to track its calls.)] TJ ET BT 61.016 542.497 Td /F4 9.0 Tf [(This is known as a)] TJ ET 0.373 0.169 0.255 rg BT 137.543 542.497 Td /F2 9.0 Tf [(mail storm)] TJ ET 0.373 0.169 0.255 RG 0.18 w 0 J [ ] 0 d 137.543 541.346 m 179.042 541.346 l S 0.153 0.153 0.153 rg BT 179.042 542.497 Td /F4 9.0 Tf [( in IT jargon when somebody replies to a single e-mail sent to a mailing list and inadvertently )] TJ ET BT 61.016 531.508 Td /F4 9.0 Tf [(replies with a personal message to the entire mailing list leading to a snowball effect or a )] TJ ET BT 415.670 531.508 Td /F2 9.0 Tf [(mail storm)] TJ ET BT 457.169 531.508 Td /F4 9.0 Tf [(. It is like a dog )] TJ ET BT 61.016 520.519 Td /F4 9.0 Tf [(chasing its own tail!)] TJ ET BT 61.016 500.530 Td /F4 9.0 Tf [(If you receive a mail with the subject line )] TJ ET BT 224.582 500.530 Td /F1 9.0 Tf [(")] TJ ET BT 228.848 500.530 Td /F4 9.0 Tf [(ICT-338035 FW: PLEASE SUPPORT STIAS - PLAN YOUR NEXT MEETING, )] TJ ET BT 61.016 489.541 Td /F4 9.0 Tf [(WORKSHOP AND OR CONFERENCE WITH US"  or "PLEASE SUPPORT STIAS - PLAN YOUR NEXT MEETING, )] TJ ET BT 61.016 478.552 Td /F4 9.0 Tf [(WORKSHOP AND OR CONFERENCE WITH US" just delete it. )] TJ ET BT 61.016 458.563 Td /F4 9.0 Tf [(If you want to take it further and set up a mail filter to delete all mails with that particular Subject, then you can do so. )] TJ ET BT 61.016 447.574 Td /F4 9.0 Tf [(However do not blacklist the sender or report it to the )] TJ ET 0.373 0.169 0.255 rg BT 274.613 447.574 Td /F4 9.0 Tf [(help@sun.ac.za)] TJ ET 0.18 w 0 J [ ] 0 d 274.613 446.423 m 339.278 446.423 l S 0.153 0.153 0.153 rg BT 339.278 447.574 Td /F4 9.0 Tf [( address or it will just perpetuate the spam, and you )] TJ ET BT 61.016 436.585 Td /F4 9.0 Tf [(could block legitimate e-mails from IT or the original sender.)] TJ ET BT 61.016 416.596 Td /F4 9.0 Tf [(Stay safe out there and thank you to everyone who flagged this email. It is encouraging when we have such observant )] TJ ET BT 61.016 405.607 Td /F4 9.0 Tf [(and enthusiastic users.)] TJ ET BT 432.949 385.618 Td /F4 9.0 Tf [([ARTICLE BY DAVID WILES])] TJ ET BT 61.016 365.629 Td /F4 9.0 Tf [( )] TJ ET 0.400 0.400 0.400 rg BT 61.016 347.140 Td /F2 9.0 Tf [(Posted in:E-mail,News,Security | | With 0 comments)] TJ ET endstream endobj 8 0 obj << /Type /Font /Subtype /Type1 /Name /F1 /BaseFont /Helvetica-Bold /Encoding /WinAnsiEncoding >> endobj 9 0 obj << /Type /Font /Subtype /Type1 /Name /F2 /BaseFont /Helvetica-Oblique /Encoding /WinAnsiEncoding >> endobj 10 0 obj << /Type /Font /Subtype /Type1 /Name /F3 /BaseFont /Helvetica-BoldOblique /Encoding /WinAnsiEncoding >> endobj 11 0 obj << /Type /Font /Subtype /Type1 /Name /F4 /BaseFont /Helvetica /Encoding /WinAnsiEncoding >> endobj 12 0 obj << /Type /Annot /Subtype /Link /A 13 0 R /Border [0 0 0] /H /I /Rect [ 135.0407 541.6642 137.5427 550.8217 ] >> endobj 13 0 obj << /Type /Action /S /URI /URI (https://en.wikipedia.org/wiki/Email_storm) >> endobj 14 0 obj << /Type /Annot /Subtype /Link /A 15 0 R /Border [0 0 0] /H /I /Rect [ 137.5427 551.2879 137.5427 551.2879 ] >> endobj 15 0 obj << /Type /Action /S /URI /URI (https://en.wikipedia.org/wiki/Email_storm) >> endobj 16 0 obj << /Type /Annot /Subtype /Link /A 17 0 R /Border [0 0 0] /H /I /Rect [ 137.5427 541.6642 179.0417 550.8217 ] >> endobj 17 0 obj << /Type /Action /S /URI /URI (https://en.wikipedia.org/wiki/Email_storm) >> endobj 18 0 obj << /Type /Annot /Subtype /Link /A 19 0 R /Border [0 0 0] /H /I /Rect [ 274.6127 446.7412 339.2777 455.8987 ] >> endobj 19 0 obj << /Type /Action /S /URI /URI (mailto:help@sun.ac.za) >> endobj xref 0 20 0000000000 65535 f 0000000008 00000 n 0000000073 00000 n 0000000119 00000 n 0000000305 00000 n 0000000334 00000 n 0000000472 00000 n 0000000575 00000 n 0000004657 00000 n 0000004769 00000 n 0000004884 00000 n 0000005004 00000 n 0000005112 00000 n 0000005240 00000 n 0000005333 00000 n 0000005461 00000 n 0000005554 00000 n 0000005682 00000 n 0000005775 00000 n 0000005903 00000 n trailer << /Size 20 /Root 1 0 R /Info 5 0 R >> startxref 5976 %%EOF E-mail « Informasietegnologie
Language:
SEARCH
  • Recent Posts

  • Categories

  • Archives

E-mail

Phishing from staff email

Monday, October 14th, 2019

An email with the subject “Purchase Order 98474” has been sent from a sun email address to staff and students. The email ask you to click on a link to open your purchase order information (also see image below)

This is not a legitimate email, but a phishing attempt from a compromised university account.

By clicking on links and providing your information, you give criminals access to your personal information and your accounts. If you think your account or device has been compromised or you notice suspicious activity:

Immediately change your password on www.sun.ac.za/password.

Contact the IT Service Desk by logging a request or calling 808 4367. 

Phishing from staff email

Monday, August 26th, 2019

Three separate emails with the subjects “Information Service”, “Online course” and “IT communication” from a compromised staff email address were sent to staff and students recently. The emails ask you to click on a link which will open an incident logged on the “Self Service Portal”, click on a link to complete a survey or activate two-factor authentication. One of these used Information Technology’s own branding to try and phish our staff and students.(also see images below)

None of these are legitimate emails, but phishing attempts from a compromised university account.

By clicking on links and providing your information, you give criminals access to your personal information and your accounts.

    • Immediately change your password on www.sun.ac.za/password.
    • Contact the IT Service Desk by logging a request or calling 808 4367.
    • More information is available on our blog and Twitter.

 

Phishing with subject “Verify Your Email To Avoid Disruption”

Friday, June 7th, 2019

An email with the subject “Verify Your Email To Avoid Disruption” which looks as if it’s from “Stellenbosch University – Outlook Office 365” was sent to staff and students. The email asks you to click on a link to verify your Outlook account. (see image)

This is not a legitimate email from Information Technology, but a phishing attempt.

We will never ask you to provide any personal information by means of email. By clicking on links and providing your information, you give criminals access to your personal information and your accounts.

If you clicked on the link in this phishing email, immediately change your password on www.sun.ac.za/password. For enquiries contact the IT Service Desk by logging a request or calling 808 4367. More information on phishing is available on our blog and Twitter.

Malware warning

Tuesday, April 16th, 2019

Emails with the subjects “Have you received your payment” and “Apply for a loan” are being distributed to students and staff. Please do not open these since they could contain an embedded file which will infect your device with malware.

When you receive emails with attachments from unknown senders, keep in mind that you should never open attachments as they could contain malicious content.

If you think your account or device has been compromised or you notice suspicious activity:

  1. Immediately change your password on www.sun.ac.za/password.
  2. Contact the IT Service Desk by logging a request or calling 808 4367.
  3. More information is available on our blog and Twitter.

Increase in phishing attacks

Wednesday, April 3rd, 2019

Phishing attacks are on the increase due to staff and students replying to phishing emails or entering their usernames and passwords on suspicious websites.

This not only poses a security risk for the user, but also for their colleagues and more importantly, for the safety of our entire university network.

Please do not reply to any email requesting your username and password, even if it’s seemingly from someone you know. This information is used by phishing attackers to target our students and staff. By supplying your private information you are making it much easier for them to access accounts and the network.

If you think your account has been compromised or notice suspicious activity:

  • Immediately change your password on www.sun.ac.za/password.
  • Contact the IT Service Desk by logging a request or calling 808 4367.
  • More information on phishing is available on our blog and Twitter.
 

© 2013-2025 Disclaimer: The views and opinions expressed in this page are strictly those of the page author(s) and content contributor(s). The contents of this page have not been reviewed or approved by Stellenbosch University.