%PDF-1.3 1 0 obj << /Type /Catalog /Outlines 2 0 R /Pages 3 0 R >> endobj 2 0 obj << /Type /Outlines /Count 0 >> endobj 3 0 obj << /Type /Pages /Kids [6 0 R ] /Count 1 /Resources << /ProcSet 4 0 R /Font << /F1 8 0 R /F2 9 0 R /F3 10 0 R /F4 11 0 R >> /XObject << /I1 28 0 R /I2 29 0 R >> >> /MediaBox [0.000 0.000 612.000 792.000] >> endobj 4 0 obj [/PDF /Text /ImageC ] endobj 5 0 obj << /Creator (DOMPDF) /CreationDate (D:20250727151138+00'00') /ModDate (D:20250727151138+00'00') /Title (Report 07-2025) >> endobj 6 0 obj << /Type /Page /Parent 3 0 R /Annots [ 12 0 R 14 0 R 16 0 R 18 0 R 20 0 R 22 0 R 24 0 R 26 0 R ] /Contents 7 0 R >> endobj 7 0 obj << /Length 4871 >> stream 0.702 0.800 0.816 rg 34.016 34.016 543.969 723.969 re f 1.000 1.000 1.000 rg 45.266 281.192 521.469 465.542 re f 0.773 0.773 0.773 RG 0.75 w 0 J [ ] 0 d 45.641 281.567 520.719 464.792 re S 0.773 0.773 0.773 rg 61.016 296.942 m 550.984 296.942 l 550.984 297.692 l 61.016 297.692 l f 0.200 0.200 0.200 rg BT 61.016 693.716 Td /F1 14.4 Tf [(REACTIVATE YOUR USERNAME BEFORE 1 APRIL)] TJ ET 0.400 0.400 0.400 rg BT 61.016 664.909 Td /F2 9.0 Tf [(Posted on )] TJ ET BT 104.045 664.909 Td /F3 9.0 Tf [(August 02,2021)] TJ ET BT 170.069 664.909 Td /F2 9.0 Tf [( by )] TJ ET BT 184.577 664.909 Td /F3 9.0 Tf [(IT Communications)] TJ ET 0.153 0.153 0.153 rg BT 61.016 637.420 Td /F4 9.0 Tf [(Network access \(usernames\) for staff will expire at the )] TJ ET BT 279.581 637.420 Td /F1 9.0 Tf [(end of March)] TJ ET BT 335.588 637.420 Td /F4 9.0 Tf [( unless youreactivate your username.)] TJ ET BT 61.016 617.431 Td /F4 9.0 Tf [(We suggest that you reactivate yours as soon as possible to ensure uninterrupted access to IT services \(internet, email, )] TJ ET BT 61.016 606.442 Td /F4 9.0 Tf [(SUN-e-HR etc.\). Keep in mind that the cost centre manager still has to approve your request before your username is )] TJ ET BT 61.016 595.453 Td /F4 9.0 Tf [(reactivated; allow sufficient time for this to be done to avoid disruption of your service.)] TJ ET BT 61.016 575.464 Td /F4 9.0 Tf [(You will receive an email from )] TJ ET 0.373 0.169 0.255 rg BT 183.047 575.464 Td /F4 9.0 Tf [(helpinfo@sun.ac.za)] TJ ET 0.373 0.169 0.255 RG 0.18 w 0 J [ ] 0 d 183.047 574.313 m 262.220 574.313 l S 0.153 0.153 0.153 rg BT 262.220 575.464 Td /F4 9.0 Tf [( indicating that your username \("engagement"\) will expire soon. Three )] TJ ET BT 61.016 564.475 Td /F4 9.0 Tf [(notifications will be sent before the end of March. Alternatively, you can go directly to the )] TJ ET 0.373 0.169 0.255 rg BT 415.184 564.475 Td /F1 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 415.184 563.045 m 465.701 563.045 l S 0.153 0.153 0.153 rg BT 465.701 564.475 Td /F4 9.0 Tf [( page.)] TJ ET BT 61.016 544.486 Td /F4 9.0 Tf [(Once logged into the)] TJ ET 0.373 0.169 0.255 rg BT 146.570 544.486 Td /F4 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 146.570 543.335 m 192.587 543.335 l S 0.153 0.153 0.153 rg BT 192.587 544.486 Td /F4 9.0 Tf [( page, you can select the services you want to reactivate. You areencouraged to read )] TJ ET BT 61.016 533.497 Td /F4 9.0 Tf [(the ECP \(Electronic Communication Policy\) before reactivating.)] TJ ET BT 61.016 513.508 Td /F4 9.0 Tf [(Choose the services \(network / email usernames and internet usernames\) you want to register for \(see images below\).)] TJ ET BT 61.016 493.519 Td /F4 9.0 Tf [()] TJ ET BT 61.016 473.530 Td /F4 9.0 Tf [(Reactivation of internet usernames is no longer necessary and can be ignored.)] TJ ET BT 61.016 453.541 Td /F4 9.0 Tf [(Make sure you select the correct cost points and if you're unsure ask your cost centre manager. Click )] TJ ET BT 465.899 453.541 Td /F2 9.0 Tf [(Accept and )] TJ ET BT 61.016 442.552 Td /F2 9.0 Tf [(Reactivate.)] TJ ET BT 61.016 422.563 Td /F2 9.0 Tf [()] TJ ET BT 63.518 422.563 Td /F4 9.0 Tf [(You will receive a notification stating that your request has been submitted, as well as a confirmation email.)] TJ ET BT 61.016 402.574 Td /F4 9.0 Tf [(The webpage will indicate that it will be activated as soon as it has been approved by the cost centre manager. When the )] TJ ET BT 61.016 391.585 Td /F4 9.0 Tf [(cost centre manager approves the reactivation request access will be extended to the end of March next year.)] TJ ET BT 61.016 371.596 Td /F4 9.0 Tf [(If you have completed these steps successfully and still receive emails from )] TJ ET 0.373 0.169 0.255 rg BT 364.631 371.596 Td /F4 9.0 Tf [(helpinfo@sun.ac.za)] TJ ET 0.18 w 0 J [ ] 0 d 364.631 370.445 m 443.804 370.445 l S 0.153 0.153 0.153 rg BT 443.804 371.596 Td /F4 9.0 Tf [( urging you to reactivate, )] TJ ET BT 61.016 360.607 Td /F4 9.0 Tf [(please go back to the )] TJ ET 0.373 0.169 0.255 rg BT 149.072 360.607 Td /F4 9.0 Tf [(reactivation)] TJ ET 0.18 w 0 J [ ] 0 d 149.072 359.456 m 195.089 359.456 l S 0.153 0.153 0.153 rg BT 195.089 360.607 Td /F4 9.0 Tf [( page and make sure the appropriate boxes are checked: Your Network / Email )] TJ ET BT 61.016 349.618 Td /F4 9.0 Tf [(usernames Your Internet usernames)] TJ ET BT 61.016 329.629 Td /F4 9.0 Tf [(If you are still not able to reactivate, please raise a request at )] TJ ET 0.373 0.169 0.255 rg BT 308.642 329.629 Td /F4 9.0 Tf [(servicedesk.sun.ac.za)] TJ ET 0.18 w 0 J [ ] 0 d 308.642 328.478 m 397.175 328.478 l S 0.400 0.400 0.400 rg BT 61.016 311.140 Td /F2 9.0 Tf [(Posted in:Connectivity,E-mail,General,Internet,News,Notices | | With 0 comments)] TJ ET q 155.250 0 0 18.000 61.016 484.310 cm /I2 Do Q endstream endobj 8 0 obj << /Type /Font /Subtype /Type1 /Name /F1 /BaseFont /Helvetica-Bold /Encoding /WinAnsiEncoding >> endobj 9 0 obj << /Type /Font /Subtype /Type1 /Name /F2 /BaseFont /Helvetica-Oblique /Encoding /WinAnsiEncoding >> endobj 10 0 obj << /Type /Font /Subtype /Type1 /Name /F3 /BaseFont /Helvetica-BoldOblique /Encoding /WinAnsiEncoding >> endobj 11 0 obj << /Type /Font /Subtype /Type1 /Name /F4 /BaseFont /Helvetica /Encoding /WinAnsiEncoding >> endobj 12 0 obj << /Type /Annot /Subtype /Link /A 13 0 R /Border [0 0 0] /H /I /Rect [ 183.0467 574.6312 262.2197 583.7887 ] >> endobj 13 0 obj << /Type /Action /S /URI /URI (mailto:helpinfo@sun.ac.za) >> endobj 14 0 obj << /Type /Annot /Subtype /Link /A 15 0 R /Border [0 0 0] /H /I /Rect [ 415.1837 573.2659 415.1837 573.2659 ] >> endobj 15 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 16 0 obj << /Type /Annot /Subtype /Link /A 17 0 R /Border [0 0 0] /H /I /Rect [ 415.1837 563.6422 465.7007 572.7997 ] >> endobj 17 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 18 0 obj << /Type /Annot /Subtype /Link /A 19 0 R /Border [0 0 0] /H /I /Rect [ 146.5697 543.6532 192.5867 552.8107 ] >> endobj 19 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 20 0 obj << /Type /Annot /Subtype /Link /A 21 0 R /Border [0 0 0] /H /I /Rect [ 61.0157 484.3099 216.2657 502.3099 ] >> endobj 21 0 obj << /Type /Action /S /URI /URI (http://blogs.sun.ac.za/it/files/2020/02/Your-Network-Email-usernames.png) >> endobj 22 0 obj << /Type /Annot /Subtype /Link /A 23 0 R /Border [0 0 0] /H /I /Rect [ 364.6307 370.7632 443.8037 379.9207 ] >> endobj 23 0 obj << /Type /Action /S /URI /URI (mailto:helpinfo@sun.ac.za) >> endobj 24 0 obj << /Type /Annot /Subtype /Link /A 25 0 R /Border [0 0 0] /H /I /Rect [ 149.0717 359.7742 195.0887 368.9317 ] >> endobj 25 0 obj << /Type /Action /S /URI /URI (https://maties2.sun.ac.za/rtad4/useradm/auth/reactivate.rtad) >> endobj 26 0 obj << /Type /Annot /Subtype /Link /A 27 0 R /Border [0 0 0] /H /I /Rect [ 308.6417 328.7962 397.1747 337.9537 ] >> endobj 27 0 obj << /Type /Action /S /URI /URI (https://servicedesk.sun.ac.za) >> endobj 28 0 obj << /Type /XObject /Subtype /Image /Width 207 /Height 24 /Filter /FlateDecode /DecodeParms << /Predictor 15 /Colors 1 /Columns 207 /BitsPerComponent 8>> /ColorSpace /DeviceGray /BitsPerComponent 8 /Length 55>> stream X 0 }nbr휿e~iO6?m~iBN endstream endobj 29 0 obj << /Type /XObject /Subtype /Image /Width 207 /Height 24 /SMask 28 0 R /Filter /FlateDecode /DecodeParms << /Predictor 15 /Colors 3 /Columns 207 /BitsPerComponent 8>> /ColorSpace /DeviceRGB /BitsPerComponent 8 /Length 1684>> stream hoHSk…CCҟ5)!4D?80Q3~X*12Dƾ(SU1aBm1naqv?E$(,5jHUϸL8v#PTbRCeŒDyS}vGϜN*hHkiURSU~qie)i0:5u|ؑRej4 Hs1S-Zk'+ˡFM!8?84`1%PsUEQHiY>epXx5#HlAN(>z:֋kZ"d]{vPjU$ LbW$!(z-a¨Y[ð* 3XGW9?8RTOo*\ qYJ(,5Z;]e`ڍuT7NgN'CaқVEF>?U-9;2E{rnzwٍMFMYܡr*m#.fPdrQH&#O ENKd,q2V27գ#^ɹ*d z0F|9?8j^InF. ={YIW2(]ZYCoKE^@ği]Ytuo-b{F'E@-YmTAFF)$ێk9q@SmiD!&_tESnO| .PBAIɰ*z (95h13j"> VQ_7AedH=K'F͒@ɓ;wh-6fUyJ˿.yԥ^uGOp?@'Qh zP9tBv,& :/`F`9ޖ پHh2ޭrH䅺.QH(ZLJڵg7%BH<f-,59! *d$ă$LIL\+oHLu[>6?ݥ#'U߿}~6m#d,Anw&f1UQ[꣧%0y7Igu̓W5Z,'8"/p:"/^EH5b z+ృK.HN_Xj B/H,Ս-g,Si7fW ?㕕_p *֋5Uօ&x$K^M*Z9%-aY)Xn n$ B٣毁r\:K`pT72 ;E!%T_>)e5(Oj7}bwq? AT!w(ަ;oS)䎼ڇkZ ma endstream endobj xref 0 30 0000000000 65535 f 0000000008 00000 n 0000000073 00000 n 0000000119 00000 n 0000000343 00000 n 0000000380 00000 n 0000000518 00000 n 0000000649 00000 n 0000005572 00000 n 0000005684 00000 n 0000005799 00000 n 0000005919 00000 n 0000006027 00000 n 0000006155 00000 n 0000006232 00000 n 0000006360 00000 n 0000006472 00000 n 0000006600 00000 n 0000006712 00000 n 0000006840 00000 n 0000006952 00000 n 0000007079 00000 n 0000007203 00000 n 0000007331 00000 n 0000007408 00000 n 0000007536 00000 n 0000007648 00000 n 0000007776 00000 n 0000007857 00000 n 0000008155 00000 n trailer << /Size 30 /Root 1 0 R /Info 5 0 R >> startxref 10097 %%EOF E-mail « Informasietegnologie
Language:
SEARCH
  • Recent Posts

  • Categories

  • Archives

E-mail

Warning: Phishing scams with fake invoices

Monday, October 1st, 2018

The nature of the university as an academic institution means that goods like books and academic journals are purchased by staff.

Phishing scammers will often exploit these purchases by either spoofing the e-mail addresses of well-known publishers or sending “invoices” that are infected with malware to fool people into divulging personal details like passwords and bank account details, or more seriously, infecting their victim’s computers with ransomware which encrypts the contents of the hard drive and demands a ransom to unlock access to the encrypted files.

Last week several colleagues reported that they were getting invoices from a journal publisher for books they allegedly purchased. An invoice for books purchased is usually attached.

Here is an example of the phishing scam:

Please keep an eye open for this threat over the next few days. We have been reading reports of a drastic increase in the incidents of ransomware infections targeting large institutions like universities. Keep on your toes, these criminals will never stop trying, because they catch their victims from the university so easily. Don’t become a victim. Fight them by reporting these scams to the IT CyberSecurity Team, and by spreading the news to your colleagues and classmates.

 If you have received mail that looks like this please immediately report it to the Information Technology Security Team using the following method: (especially if it comes from a university address) Once you have reported it, delete it or put it in your Junk Mail folder.

  1. Start up a new mail addressed to csirt@sun.ac.za, cc sysadm@sun.ac.za.
  2. Use the Title “SPAM” (without quotes) in the Subject.
  3. With this New Mail window open, drag the suspicious spam/phishing mail from your Inbox into the New Mail Window. It will attach the mail as an enclosure and a small icon with a light yellow envelope will appear in the attachments section of the New Mail.
  4. Send the mail.

[ARTICLE BY DAVID WILES]

 

SARS phishing scam from sun email

Monday, August 13th, 2018

If you receive an email with the subject “SARS eFilings” from any university email account, do not respond or click on the link. This is not a legitimate email from SARS.

The suspicious email is being sent from compromised staff email accounts informing users that “An EMP Statement of Account for the tax payer listed below has been issued by SARS” and you “need to log into the google doc with your correct details to view the document”. (as shown in example below):

It is important that you help us by spreading the word, informing us about suspicious mails and letting your colleagues and friends know about the scams. You are our eyes and ears, and your input, information and questions are extremely valuable.

When you click on links and provide your information on phishing emails, criminals will be able to gain access to your personal information. If you clicked on the link of this phishing email, immediately go to the www.sun.ac.za/useradm website and change the passwords on all your university accounts.

Remember that once the phishers lose control of one compromised account they might simply move over to another account and they might also close the website they were using once it is blocked by us and would use another one that looks and acts in the same way. Currently, the phishers are servers in Europe to launch their attacks. This is a common tactic with a spear-phishing attack such as this. 

To help us, please:

  • continue to watch out for mail like or similar to this and do NOT respond to it, click on links or provide your email address username or password
  • report the new phishing mail to the correct e-mail addresses of Information Technology Cyber Security using the method added to the bottom of this post
  • remember, just because a mail comes from a “student” or a “personnel” e-mail address and has university branding does not mean in any way that it is legitimate

If you have received mail that looks like this please immediately report it to the Information Technology Security Team using the following method: (especially if it comes from a university address)

  1. Start up a new mail addressed to sysadm@sun.ac.za (CC: help@sun.ac.za)
  2. Use the Title “SPAM” (without quotes) in the Subject.
  3. With this New Mail window open, drag the suspicious spam/phishing mail from your Inbox into the New Mail Window. It will attach the mail as an enclosure and a small icon with a light yellow envelope will appear in the attachments section of the New Mail.
  4. Send the mail.

IF YOU HAVE FALLEN FOR THE SCAM:

If you did click on the link of this phishing spam and unwittingly give the scammers your username, e-mail address and password you should immediately go to http://www.sun.ac.za/useradm and change the passwords on ALL your university accounts (making sure the new password is completely different, and is a strong password that will not be easily guessed.) as well as changing the passwords on your social media and private e-mail accounts (especially if you use the same passwords on these accounts.)

For more information on reporting and combating phishing and spam: https://blogs.sun.ac.za/it/en/2017/11/reporting-spam-malware-and-phishing/

[Information supplied by David Wiles]

 

Before you resign or retire …

Tuesday, July 31st, 2018

You’ve packed up your office, said goodbye to your colleagues and you are ready for your new job. But what happens to your sun email address, your data or any electronic services you used while working at Stellenbosch University? We have a few tips and instructions. 

As soon as your active role as staff expires, all your electronic services also terminate. This process is necessary to maintain a healthy and secure network and to ensure that unused, dormant accounts are not used for nefarious purposes by cybercriminals.

In other words, from the date when your service at SU is terminated, you no longer have an active role at the university and you can no longer use university services. In this event, you will receive an email from helpinfo@sun.ac.za informing you that your username will expire.

To ensure that you are prepared in advance, we also suggest you do the following at least three months before you leave the university:

  1. Create a new email address for yourself (if you don’t have one already) There are various options, for example, Gmail or Yahoo.
  2. Activate your Out of Office function on you sun.ac.za Outlook mailbox and indicate in the message what your new email address is, in case someone needs to contact you. 
  3. If you use your @sun address for your banking, Facebook, DSTV or iCloud accounts or any other services or social media, change it to your new email address. We would also like to urge you to keep your work-related and private emails separate. Rather create a private email address for your personal correspondence.
  4. If you have any personal data on your electronic work devices or network storage (G: or H: drive), remove it and store it on your own external hard drive or online cloud storage, for example, Google Drive or OneDrive
  5. Make sure that your relevant work-related data is accessible for further usage by your colleagues and the university after you leave. However, do NOT give your password to colleagues when you leave the university as this poses a security risk.
  6. If you need any assistance, contact Information Technology and one of our technicians can assist you.

Students who are graduating or terminating their studies can find the necessary information on this pamphlet compiled by the IT HUB.

Warning: Phishing scam exploiting ABSA new logo

Tuesday, July 17th, 2018

Many of you use ABSA as your bank of choice, as well as making use of ABSA Bank’s Internet Banking facilities, so this warning might be of particular significance.

Earlier this month ABSA announced a new logo – part of its rebranding campaign – and almost immediately phishing scammers exploited this opportunity to continue their nefarious campaign of identity theft through phishing email attacks.

Several users have reported getting the following email – allegedly from ABSA – taking advantage of the new logo to target the bank’s customers in a phishing email scam by attempting to trick users to click on a link to take them to a fake website.

The scam email states that it comes from Absa CEO Maria Ramos, but it’s actually from an outside source and informs victims that “today marks a very significant day in the Absa journey”. The email uses Absa’s slogan, saying “We are also launching a new, fresh and vibrant Absa logo and identity that reflects our commitment to you, our customers”. Potential victims are then encouraged to click on their “New Absa eStatements” in PDF format. This is not a statement, but an HTML file which takes users to a phishing website.

Here is one example of the phishing e-mail which has already appeared in several University email accounts, as well as personal home email accounts:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

As always, you should never respond to a suspicious looking email or message or click on a link in any suspicious looking email. Rather delete the email. No South African bank will ever contact customers and request sensitive information (card PIN, card CVV or online banking password) via email, telephone or SMS.

If you have received a phishing email, immediately report it to the Information Technology CyberSecurity Team using the following method:
 
1. Start up a new mail addressed to sysadm@sun.ac.za (CC: help@sun.ac.za)
2. Use the Title “SPAM” (without quotes) in the Subject.
3. With this New Mail window open, drag the suspicious spam/phishing mail from your Inbox into the New Mail Window. It will attach the mail as an enclosure and a small icon with a light yellow envelope will appear in the attachments section of the New Mail.
4. Send the mail.

IF YOU HAVE FALLEN FOR THE SCAM:
If you did click on the link of a phishing spam and unwittingly gave the scammers your username, email address and password  immediately go to http://www.sun.ac.za/useradm and change the passwords on ALL your university accounts (making sure the new password is completely different and is a strong password that will not be easily guessed.), as well as changing the passwords on your social media and private email accounts (especially if you use the same passwords on these accounts.)
 
Useful information on how to report and combat phishing and spam can also be found on our blog

[ARTICLE BY DAVID WILES]

Phishing attempt from SUN email address

Monday, June 25th, 2018

If you receive an email with the subject “Mailbox” or “Urgent Alert !!” from a university account, do not respond to it or click on the link. This is not a legitimate email from Information Technology.

We have received reports that a suspicious email is being sent out from a university account informing users that their email has exceeded its storage limit and they have to click on a link to “avoid blockage or deactivation”(As shown in example)

If you follow the link and give your information, it will be used by phishing criminals to gain access to your personal information, including your bank details. If you did click on the link of this phishing email, immediately go to the www.sun.ac.za/useradm website and change the passwords on all your university accounts.

If you have any inquiries, please let us know by logging a request or calling our Service Desk at 808 4367. 

 

© 2013-2025 Disclaimer: The views and opinions expressed in this page are strictly those of the page author(s) and content contributor(s). The contents of this page have not been reviewed or approved by Stellenbosch University.