OIT Tech 32px
Shop online securely this holiday season
Outage report: Oracle e-Business & related apps, Nov 12, 2015
Password managers help ensure online security
Outage report: File storage on shared.ohio.edu, Oct. 7; Blackboard Learn, PeopleSoft & e-Biz, Oct 12, 2015
ITSS 2015 Schedule
2015 IT Security Seminar
Making the digital world more accessible: ADA 25 Celebration Series
Bobcat Depot takes over background checks from OUPD
What we can learn from a broken Internet
Outage report: Network, Oct. 1, 2015

Email scams on the rise: What you can do

Thursday, April 17, 2014
Sean O'Malley  

University employees should be on the lookout for fraudulent emails that ask them to provide their OHIO ID and password, log into a secure site, or confirm their personal or account information.

"The Internet security community is reporting an increase in attacks aimed at university employees, with the goal of modifying their paycheck direct deposit settings," said security analyst Ed Carter. According to Carter, the messages used in these "spear phishing" attacks are carefully designed to include phrases, web sites, and links that are specific to the school being targeted.

Many of these scams can look quite convincing, but Carter says one simple rule can keep you from having your credentials - and possibly your paycheck - stolen.

Don't send, don't click

If you receive an unsolicited email asking you to do any of the following, don't do it:

  • send someone your OHIO ID and password
  • click on a link
  • open an attachment
  • provide sensitive information like your Social Security number

Legitimate requests

If OIT needs you to log into a web page, that page will not be clickable inside the message. Instead, we will include instructions on how to reach that link from the OHIO front door. For example, in a recent message to users who might have been affected by the Heartbleed security bug, we included the following instructions:

To change your password, look for a link on any of these OHIO web pages:

  • Students page
  • Employees page
  • Information Technology home page

None of those bulleted items was clickable - by design. The recipient had to open a web browser, type in "www.ohio.edu" and then navigate to one of the named pages.

Related Links

University of Michigan warns against email scams as some direct deposit accounts are compromised 
Internet scammers change some BU direct deposit accounts
Watch out for email scams