ACC Mail ACC ACC Homepage
About ACCACC NewsFaculty Services IndexStudent Services IndexACC User DocumentationACC Computing PoliciesRecommended Systems and Purchase informationComputer Support Services
 

Security Bulletin of January 5, 2009

Overview
Full Text of One Known Scam
Tips for Safer Computing
Further Assistance

Other Bulletins
Recent CERT Alerts

COMPUTING ALERT: Beware of Email Scam/Phishing Attempts

OVERVIEW

Several Haverford email users recently received an email message with the subject line "Web-E-News / http://www.haverford.edu Email Account Update!!" requesting their user name and password. DO NOT RESPOND!

This is a spam message, known as "phishing," and is a common type of malicious email. By pretending to be a trustworthy source, the spammer tries to trick you into revealing sensitive information like email passwords or bank account information.

If you recently replied to an email requesting your Haverford account password, reset your password immediately. Our password changing tool is on our secure web site, https://accounts.haverford.edu/. (How can you tell the site is secure? Notice that the URL begins with HTTPS and that your browser displays an image of a padlock on the URL line or the status bar, indicating the site is verified and encrypted.)

GENERAL TIPS:

A few general guidelines for identifying suspicious messages:

-- Don't trust messages that ask for sensitive information like account numbers and email passwords. Email is not secure. Reputable sources, including the computing center, should never ask you to send sensitive information by email.

--  Don't trust email attachments you aren't expecting. Such attachments may be a virus or other malicious file.  ACC will never email an executable file. Instead, if we ask you to take action, we will always refer you to our web site.

--  Be wary of get-rich-quick and quick-fix emails.  If it looks too good to be true, it probably is.

--  Use common sense.  In addition to the issues mentioned above, there are many other potential email hazards. If you have any doubt about a message, check with the sender or with the computing center.

For more tips, the United States Computer Emergency Response Team published an excellent document, Recognizing and Avoiding Email Scams, on their web site (https://www.us-cert.gov/reading_room/).

FULL TEXT OF ONE KNOWN SCAM

The full text this bogus email message is below.

From: IT ADMIN DESK <admininfosdept@gmail.com>
Date: Fri, Jan 2, 2009 at 12:16 PM
Subject: Web-E-News / http://www.haverford.edu Email Account Update!!


HARVERFORD

Dear haverford.edu Email Account Owner,
 
This message is from haverford.edu messaging center to all EDU email account owners.
On 3rd and 7th January, 2009, from 11:45 PM until 7:20 AM,
all Mail hub systems in the Portal will under go regularly scheduled maintenance
in EDU. Access to your e-mail via the Web mail client may be unavailable for some
time during this maintenance window to all haverford.edu email account owners.We are
currently upgrading our data base and e-mail account center.
We are deleting all haverford.edu email account to create more space for new accounts.
 
To prevent your account from closing you will have to update it below so
that we will know that it's a present used account.
 
To complete your EDU Web mail account, you must reply to this email immediately and
enter your ACCOUNT USERNAME here (_________)
CORRECT PASSWORD here (________) immediately for upgrading,
Once we have updated your account, current records will be sent to your Online
Account and your service will not be interrupted and will continue working as normal.

Email here in words:(********)
Email password here in words:(******)
Date of Birth:(*******)
You can also confirm your email address by logging into your
www.haverford.edu Webmail account at
http://webmail.haverford.edu

If you need help to take advantage of this new service please
contact the appropriate support staff.
 
 
Failure to do this will immediately render your email address
deactivated from our database after 7 days.
 
Warning!!! Account owner that refuses to update his or her account within
Seven days of receiving this warning will lose his or her
account permanently.
Thank you for using www.haverford.edu Webmail Gateway
Warning Code:VX2G99AAJ
 
Thanks,
www.haverford.edu Webmail Team
************************************************************************
************************************************************************


FOR FURTHER ASSISTANCE

Students, faculty and staff please contact the Computing Center Help Desk:
Telephone: 610-896-1480
Email: helpdesk@haverford.edu
Web: http://www.haverford.edu/acc/helpdesk/
Location: Stokes 204

MORE INFORMATION

Additional information about computer security and current threats can be found at the following sites:

United States Computer Emergency Readiness Team (US-CERT )
<https://www.us-cert.gov/nav/nt01/>
McAfee Avert Threat Center
<https://www.mcafee.com/us/threat_center/default.asp>
Microsoft Security
<https://www.microsoft.com/security/>
Apple Product Security
<https://www.apple.com/support/security/>

ACC EMAIL POLICY:

ACC will never request passwords or other confidential information via email. Email is not secure. We will never email an executable file. Instead, if we ask you to take action, we will always refer you to our web site, using an address that starts with the secure "https" protocol -- that way, you know you are downloading a safe file from us.

VERIFY THIS ALERT IS LEGITIMATE:

Before taking an action recommended in an email, please confirm that the email is legitimate. ACC posts a detailed description of all our alerts on our web site, https://www.haverford.edu/acc/bulletins/.

For Questions and Comments, contact Haverford College's Academic Computing Center.
Last updated on January 5, 2009

HC HomeCampus DirectoryHaverford College Library ResourcesHaverford College Web Search EngineAcademic DepartmentsACC Home