{"id":12675,"date":"2017-12-13T11:41:48","date_gmt":"2017-12-13T09:41:48","guid":{"rendered":"http:\/\/blogs.sun.ac.za\/it\/?p=12675"},"modified":"2017-12-13T14:13:45","modified_gmt":"2017-12-13T12:13:45","slug":"phishing-email-from-stellenbosch-university-helpdesk","status":"publish","type":"post","link":"https:\/\/blogs.sun.ac.za\/it\/2017\/12\/phishing-email-from-stellenbosch-university-helpdesk\/","title":{"rendered":"[:en]Phishing: Email from &#8220;Stellenbosch University Helpdesk&#8221;[:]"},"content":{"rendered":"<p>[:en]<\/p>\n<p>This morning\u2019s spear-phishing attack comes in the form of a fake mail from \u201cHelpDesk\u201d about an alleged \u201cEmail Update\u201d<\/p>\n<p>The spear-phishing mail is as follows:<\/p>\n<p><em>\u201cNotice From\u00a0Stellenbosch University\u00a0HelpDesk:\u00a0<\/em><\/p>\n<p><em>In an effort to increase the level of security for our \u00a0email accounts User, We are implementing a new email password policy for your protection. If you have not update your password recently click here:\u00a0<\/em><a href=\"http:\/\/blogs.sun.ac.za\/it\/en\/2017\/11\/reporting-spam-malware-and-phishing\/\">sun.ac.za<\/a>\u00a0<em>to update your password or your e-mail will be temporarily \u00a0suspended .<\/em><\/p>\n<p><em>Thanks for your co-operation.\u201d<\/em><\/p>\n<p>This is, of course, a phishing scam and you shouldn&#8217;t consider it as legitimate even though it allegedly comes from the \u201cHelpdesk\u201d.<\/p>\n<p>The poor grammar, lack of official branding and threatening tone of the mail makes it a classic phishing scam, but with the added danger of students and personnel falling for it because of the\u00a0 salutation <em>\u201cNotice from the Stellenbosch University HelpDesk:\u201d<\/em><\/p>\n<p>We have already blocked access to the server, but there is a high risk that users who are currently on holiday and accessing university mail through their ADSL internet connections or cell phone, will still have access to the scammer\u2019s server and will be fooled by the \u201cforged\u201d login page and provide the scammers with their usernames and passwords. If this happens the scammers will gain control over the personnel or student account and continue their attack from \u201cwithin\u201d the university network.<\/p>\n<p>Always send the spam\/phishing mail to the following addresses:<\/p>\n<p><a href=\"mailto:help@sun.ac.za\">help@sun.ac.za\u00a0<\/a>and <a href=\"mailto:sysadm@sun.ac.za\">sysadm@sun.ac.za<\/a>.<\/p>\n<p>\u00a0Attach the phishing or suspicious mail on to the message if possible. There is a good tutorial on how to do this at the following link <em>(which is safe) <\/em>: <a href=\"http:\/\/stbsp01.stb.sun.ac.za\/innov\/it\/it-help\/Wiki%20Pages\/Spam%20sysadmin%20Eng.aspx\">http:\/\/stbsp01.stb.sun.ac.za\/innov\/it\/it-help\/Wiki%20Pages\/Spam%20sysadmin%20Eng.aspx<\/a><\/p>\n<ol>\n<li>Start up a new mail addressed to <a href=\"mailto:sysadm@sun.ac.za\">sysadm@sun.ac.za<\/a> (CC: <a href=\"mailto:help@sun.ac.za\">help@sun.ac.za<\/a>)<\/li>\n<li>Use the Title \u201cSPAM\u201d <em>(without quotes)<\/em> in the Subject.<\/li>\n<li>With this New Mail window open, drag the suspicious spam\/phishing mail from your Inbox into the New Mail Window. It will attach the mail as an enclosure and a small icon with a light yellow envelope will appear in the attachments section of the New Mail.<\/li>\n<li>Send the mail.<\/li>\n<\/ol>\n<p><u>IF YOU HAVE FALLEN FOR THE SCAM:<\/u><\/p>\n<p>If you did click on the link of this phishing spam and unwittingly give the scammers your username, e-mail address and password you should immediately go to <a href=\"http:\/\/www.sun.ac.za\/useradm\">http:\/\/www.sun.ac.za\/useradm<\/a> and change the passwords on ALL your university accounts (making sure the new password is completely different, and is a strong password that will not be easily guessed.) as well as changing the passwords on your social media and private e-mail accounts (especially if you use the same passwords for these accounts.)<\/p>\n<p>IT has set up a website page with useful information on how to report and combat phishing and spam. The address is:<\/p>\n<p><a href=\"http:\/\/blogs.sun.ac.za\/it\/en\/2017\/11\/reporting-spam-malware-and-phishing\/\">http:\/\/blogs.sun.ac.za\/it\/en\/2017\/11\/reporting-spam-malware-and-phishing\/\u00a0<\/a>As you can see the address has a sun.ac.za at the end of the domain name, so it is legitimate.\u00a0<\/p>\n<p>[:]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[:en] This morning\u2019s spear-phishing attack comes in the form of a fake mail from \u201cHelpDesk\u201d about an alleged \u201cEmail Update\u201d The spear-phishing mail is as follows: \u201cNotice From\u00a0Stellenbosch University\u00a0HelpDesk:\u00a0 In an effort to increase the level of security for our \u00a0email accounts User, We are implementing a new email password policy for your protection. If [&hellip;]<\/p>\n","protected":false},"author":259,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20382,20381,29187],"tags":[20381,48692],"class_list":["post-12675","post","type-post","status-publish","format-standard","hentry","category-email","category-phishing","category-security-2","tag-phishing","tag-spear-phishing"],"publishpress_future_action":{"enabled":false,"date":"2026-05-22 04:59:18","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12675","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/users\/259"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/comments?post=12675"}],"version-history":[{"count":2,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12675\/revisions"}],"predecessor-version":[{"id":12677,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12675\/revisions\/12677"}],"wp:attachment":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/media?parent=12675"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/categories?post=12675"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/tags?post=12675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}