Most know better than to wire money to a Nigerian prince — but today’s scammers have adapted their strategies, according to Charron Andrus, associate chief information security officer at UC Berkeley.
“Phishing,” according to UC Berkeley’s Information Security Office, is when “cyber criminals trick you into giving them your personal information, like passwords or credit card details, by pretending to be a legitimate company or person.” To do this, they often send fake emails and messages, or even create fake websites.
Undoubtedly, phishing has made its way to UC Berkeley. The ASUC Communications email account was hacked, and unauthorized phishing messages were sent from its email address to additional recipients before the ASUC Communications team could recover the account.
The ASUC Communications email account received a phishing message on Aug. 11 disguised as a Google Docs proposal, according to ASUC Chief Communications Officer Juliette Rackohn. The phishing email came from a hacked UC Berkeley email address with which the ASUC Communications account had previously corresponded.
The ASUC account and the hacked UC Berkeley account were secured, though not before unauthorized messages were sent to other recipients, according to Rackohn.
“If attackers compromise your CalNet ID, they may be able to gain access to your personal and academic information,” Andrus said in an email. “This includes your email and calendar contents, personal identification details, financial and banking information … and stored documents and files. The consequences can be serious and far-reaching.”
Phishing scams occur year-round, and UC Berkeley itself receives thousands of suspicious emails. Andrus observed notable spikes at the start of semesters, during tax season and around holidays, when faculty and staff are juggling multiple things and are prone to distraction.
To help the community recognize these scams, UC Berkeley’s Information Security Office provides guidance on recognizing and avoiding potential scams on its Phish Tank website.
A frequent type of scam is one that pressures victims to communicate outside Berkeley systems, often including fake job offers, suspicious text messages and calendar invites containing malware, according to Andrus. Another new scam involves cybercriminals stealing login credentials and then bombarding users with multiple multi-factor authentication requests in hopes that they will approve a malicious one.
“If you see your login attempts coming from unexpected locations, such as Idaho when you’re in Berkeley, that’s a red flag,” Andrus said in an email.
Although campus has several protections against cyberattacks, such as email filtering, multi-factor authentication systems and security awareness resources, the most important thing one can do is stay vigilant, according to Andrus.
“Always best to err on the side of caution,” Rackohn said in an email, “and when in doubt, do not click.”