|
A rash of recent phishing attempts against University of Idaho
users warrants this note about "phishing" and reminds us that
all our accounts are important to overall University security
and reputation.
Q: What is phishing?
A: Phishing is a social engineering attempt to obtain personal
information such as credit cards, bank accounts, usernames and
passwords by masquerading as a user or entity you trust. This is
typically performed through an email or instant message
requesting you to enter this information in a reply or on a
website.
Q: What does the current attempt look like?
A: The latest attack is forged to appear to come from helpdesk@uidaho.edu but
asks for replies to be sent to a yahoo.com email address with
the subject "Quarantine Maintenance" and asks the user to supply
a username and password or their account will be closed.
Q: I received a phishing attempt that is not like the one
mentioned above. How do I report it?
A: Forward the message with complete message headers to abuse@uidaho.edu or
the ITS Help Desk. Instructions for including message headers
can be found on the support website at
http://support.uidaho.edu/FAQ/index.htm#Headers
Q: How do I know a message from the Help Desk is legitimate?
A: The ITS Help Desk would never ask you to put sensitive
information into an email as it is an insecure transport
mechanism. If in doubt, call the Help Desk at 885-HELP(4357) or
visit the support website
http://support.uidaho.edu/ for the latest news. No major
system change would be implemented without prior notification.
Q: I fear my account has been compromised or my password is not
secure enough, how do I change my password?
A: The only officially supported method to change your password
is on http://support.uidaho.edu under
"Account Management". Any request to change your password
through another method should be approached with extreme
suspicion. If you suspect your account has been compromised or
used by another user, report this to security@uidaho.edu or
the Help Desk and change your passwords immediately.
|