{"id":4574,"date":"2018-10-03T13:39:03","date_gmt":"2018-10-03T18:39:03","guid":{"rendered":"https:\/\/mitchellhamline.edu\/technology\/?p=4574"},"modified":"2018-10-03T13:48:25","modified_gmt":"2018-10-03T18:48:25","slug":"technology-notice-active-phishing-campaign-targeting-student-email-accounts","status":"publish","type":"post","link":"https:\/\/mitchellhamline.edu\/technology\/2018\/10\/03\/technology-notice-active-phishing-campaign-targeting-student-email-accounts\/","title":{"rendered":"Technology Notice &#8211; Active Phishing Campaign Targeting Student Email Accounts"},"content":{"rendered":"<p>The US Department of Education&#8217;s Federal Student Aid office has identified a malicious phishing campaign aimed at defrauding students of their refunds and aid distributions.<\/p>\n<p>Several schools have reported that attackers are using a phishing email to obtain access to student accounts on the student portal (see example phishing email screenshot below, courtesy of FSA). The attackers have done some level of research and understand the schools\u2019 use of student portals and methods. These attacks are successful in part due to student compliance in providing requested information.<\/p>\n<p><a href=\"https:\/\/mitchellhamline.edu\/technology\/wp-content\/uploads\/sites\/42\/2018\/10\/083118PhishingTargetStudentEmail.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4575 alignnone\" src=\"https:\/\/mitchellhamline.edu\/technology\/wp-content\/uploads\/sites\/42\/2018\/10\/083118PhishingTargetStudentEmail.png\" alt=\"\" width=\"700\" height=\"384\" srcset=\"https:\/\/mitchellhamline.edu\/technology\/wp-content\/uploads\/sites\/42\/2018\/10\/083118PhishingTargetStudentEmail.png 946w, https:\/\/mitchellhamline.edu\/technology\/wp-content\/uploads\/sites\/42\/2018\/10\/083118PhishingTargetStudentEmail-300x165.png 300w, https:\/\/mitchellhamline.edu\/technology\/wp-content\/uploads\/sites\/42\/2018\/10\/083118PhishingTargetStudentEmail-768x421.png 768w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/a><\/p>\n<p>Upon gaining access to the portal via the login provided by the student, the attacker changes the student\u2019s direct deposit destination to a bank account controlled by the attacker, and any subsequent federal student aid refunds will be stolen from the student.\u00a0 FSA believes that attackers are practicing and refining the scheme on a smaller scale now and that this will emerge as a prominent threat against schools during periods when federal student aid funds are disseminated in large volumes.<\/p>\n<p>Mitchell Hamline advises students to always be careful when entering personally identifiable information on web forms.\u00a0 Be vigilant and skeptical when receiving emails with links asking for information.\u00a0 Watch for sender&#8217;s email addresses that don&#8217;t match the sender&#8217;s supposed identity and scrutinize URLs closely.\u00a0 More information on recognizing and preventing phishing attempts can be found on the US Federal Trade Commission website at\u00a0<a href=\"https:\/\/www.consumer.ftc.gov\/articles\/0003-phishing\">https:\/\/www.consumer.ftc.gov\/articles\/0003-phishing.<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Mitchell Hamline Information Technology<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US Department of Education&#8217;s Federal Student Aid office has identified a malicious phishing campaign aimed at defrauding students of their refunds and aid distributions. Several schools have reported that attackers are using a phishing email to obtain access to student accounts on the student portal (see example phishing email screenshot below, courtesy of FSA). &hellip; <\/p>\n<p><a href=\"https:\/\/mitchellhamline.edu\/technology\/2018\/10\/03\/technology-notice-active-phishing-campaign-targeting-student-email-accounts\/\" class=\"more-link\">Technology Notice &#8211; Active Phishing Campaign Targeting Student Email Accounts<\/a><\/p>\n","protected":false},"author":10027,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[4,2,3],"tags":[],"class_list":{"0":"post-4574","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-facultystaff","7":"category-news","8":"category-students","9":"entry"},"acf":[],"_links":{"self":[{"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/posts\/4574","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/users\/10027"}],"replies":[{"embeddable":true,"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/comments?post=4574"}],"version-history":[{"count":0,"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/posts\/4574\/revisions"}],"wp:attachment":[{"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/media?parent=4574"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/categories?post=4574"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mitchellhamline.edu\/technology\/wp-json\/wp\/v2\/tags?post=4574"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}