What should you do if you receive a suspicious email?
- Do not open any attachments or click on included links.
- Please
to soc@uwaterloo.ca
(UW-IST Security Operations Centre).
Cc Michael (mwagoner@uwaterloo.ca), Gordon (gboerke@uwaterloo.ca) and myself (bee@uwaterloo.ca) so that we also have a handle on the sort of things folks in the department are receiving.
-
If you feel the message violates
Canada's anti-spam legislation
you might also want to consider
reporting it as spam
to the Government of Canada - I find forwarding as an attachment to
spam@fightspam.gc.ca
is less trouble than going through the form.
- To ensure no other messages from the sender arrive in the future, while viewing it in Outlook, you might also want to click "Junk / Block sender". Maybe also consider going into the "Junk / Junk E-mail Options" and add @thedomain to the blocked senders list so that you won't see any messages from anyone in that domain.
- Delete the original message.
- Stop gritting your teeth.
Forwarding as an attachment includes additional delivery details
that a regular forward does not include which better helps to
determine how the message arrived and who the actual sender was. IST can then also block the sender and contact the service provider it arrived through. If it appears to be widespread, they can potentially remove the message from the Inbox of other UW users before they view it.
With this additional information:
- IST SOC can determine where the message originated from, the servers it went through to be delivered in order to clock or report to a service provider.
- IST SOC can determine if it was sent from a compromised UW user on campus
or if was the case the From field was forged.
- If it's determined a UW account was compromised, IST SOC can disable the account immediately to prevent the spread of additional messages.
- If the message is widespread on campus and convincing, IST SOC may consider notifying the campus community, blocking/removing link access from
campus sites, and/or possibly fine-tuning campus email filters.
- If IST SOC knows about it early enough, there's also the possibility they can remove the message from UW Inboxes before people see it, so you're doing everyone a favour the sooner you report it.
Details
Phishing
is the bad guys' attempt to steal your userid/password so that
they can login to your accounts, steal confidential information in
your files/emails, or to use your computer accounts for sending spam,
hosting porn, etc.
IST also reminds people that
Phishing season, open all year round!
They also have information on
Cyber Awareness.
For what appear to be UW-related emails, if you notice the address
you would be replying to, or the URL you are directed to is not under
uwaterloo.ca, it's a dead giveaway that it's bogus. In general, there's
really never a need for you to share your password with anyone at
any time.
As usual, if you get'em, just chuck'em. If you have responded, let
us know and we'll investigate and ensure your various passwords are
changed ASAP.
See also:
Jump to
- the beeHive
- UW Psychology
- UWInfo Home Page.
bee@uwaterloo.ca