Snynet Solution Logo
MON - SUN: 10 AM - 6 PM
+60 11 5624 8319

Blog

Students targeted with university-themed phishing emails

Image Description

A new phishing campaign has been discovered that looks to impersonate communications from universities. Like many other phishing attacks, the scam aimed to trick individuals into handing over their Office 365 credentials.

Cloud-based email security firm Zix discovered the attack back in October, after identifying suspicious activity coming from legitimate university .EDU servers. Threat actors would sometimes impersonate a university’s IT department, asking targets to take action if they wanted to keep their Office 365 password the same before a fictitious expiry deadline passed.

Potential phishing victims were then redirected to a domain that asked visitors to authenticate themselves by entering their Office 365 usernames and passwords – unwittingly handing them over to the attacker. A similar technique was employed in order to steal Outlook credentials.

Phishing season

The AppRiver team at Zix identified this phishing campaign as particularly noteworthy for the way that it bypassed a number of sender verification checks, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC).

Although corporate phishing campaigns attract much of the attention, scams targeting the education sector are not uncommon. In October, Malwarebytes highlighted another phishing attack that was directing efforts against universities and schools.

More generally, phishing campaigns seemed to have thrived this year, with threat actors taking advantage of the confusion and misinformation that has surrounded the coronavirus pandemic. Zix has recommended that organizations, whether in the corporate or education sector, become better prepared for the many phishing threats circulating today. In addition to investing in a robust email security solution, organizations should also train their staff to remain vigilant against suspicious emails.

Via Zix

Date

14 Dec 2020

Sources


Share


Other Blog

  • Apple TV app: everything you can do with the surprisingly versatile streaming app

    The Apple TV app brings together a whole range of streaming services together in one handy place. Here's how to channel its power.

    Read More
  • Website builder growing into a billion dollar business for GoDaddy

    GoDaddy financial results show strong growth in revenue and customer numbers.

    Read More
  • Intel defends against AMD Ryzen 5000 with tease of 11th Gen Rocket Lake info

    Intel Rocket Lake-S is coming in early 2021, but now we have a tiny bit of information to go along with that knowledge.

    Read More
  • As demand for more content rises, Zee5 partners with TVF

    The Viral Fever (TVF) originals and upcoming seasons of its popular titles will stream on Zee5 as part of a partnership announced by the streaming giants.

    Read More

Find Out More About Us

Want to hire best people for your project? Look no further you came to the right place!

Contact Us