University e-mail accounts attacked by fake KU Credit Union e-mails

Phishing e-mails claiming to be from the KU Credit Union have been arriving in the KU account inboxes of students, staff and faculty.

The e-mails ask recipients to verify personal account information.

Julie Fugett, information security analyst for the IT Security Department, said the e-mails have been a staged attack, which allowed the e-mails to become more advanced over time.

The first string of e-mails appeared in April and claimed to be from the University Help Desk. Those e-mails asked students to verify their account information such as user names and passwords. Fugett said the hackers then sent e-mails from those KU e-mail accounts.

“That is part of the reason they look real,” Fugett said. “Another part is that the bad guys are getting better at what they do. They’ve started adding things like security notices.”

The link in the e-mail asked students to verify their account information but Fugett said that when people replied, they were actually allowing their information to be harvested.

Fugett said the same thing happened when people entered their debit or credit card information and social security numbers.

“They want to steal as much information from you as possible so they can spend your money,” Fugett said.

Joe Nasternak, Kansas City, Kan., senior, said he first received an e-mail claiming to be from the Credit Union in late May. Since then, he has received about four more e-mails.

“I had a feeling it wasn’t real, especially since I don’t have an account with the KU Credit Union,” Nasternak said. “That was my red flag.”

Nasternak said that he thought the e-mail looked legitimate, however, because of its format and the link it included.

“The only things that they messed up were some grammatical errors that the Credit Union wouldn’t make,” he said. “Other than that I could see how someone would think it was real.”

Fugett said that the e-mails were especially innovative because they were able to bypass the University’s spam filters. She said that the IT Security Office did its best to filter spam e-mail, but that because it wanted to let all legitimate e-mails through, sometimes bad e-mails got past the system.

Bill Myers, director of information services, said that he didn’t know when the e-mails would be phased out of the system. He said that the Security Office filtered about 3 million to 5 million spam e-mails out of the system per day.

“It’s way more than what ever gets into inboxes,” he said. “Spammers are always looking for ways to penetrate the network.”

Fugett said the Security Office had been working to combat the problem by sending anyone who was logged onto a computer within the University network to the Security Office’s Web site when they clicked on the link.

“The situation was getting dire enough that we said we had to do something, so that’s what we decided to do,” Fugett said.

If you’ve responded to the e-mail and given out your personal information, call the University Customer Service Center at (785) 864-8080.

—Edited by Case Keefer

 

Related articles

University alerts network users to phishing

A fraudulent e-mail asked students and faculty to provide their usernames and ...

/news/2008/aug/22/Phishing/

Text message scam targets students

A mass text message sent on Feb. 1 was quickly determined to ...

/news/2011/feb/12/students-receive-text-message-scam/

E-mail frauds target University students

Many students received e-mails from somebody posing as a representative from the ...

/news/2007/nov/19/email/

Facebook accounts pose dangers

Incriminating information online can both endanger student security and harm future career ...

/news/2007/oct/16/facebook_accounts_pose_dangers/

Workshop teaches warnings signs of cyber scams

Phishing scams have Internet users on edge.

/news/2010/feb/03/cyber-scams/

University battles SPAM

/news/2006/feb/22/spam/

On-campus e-mail gets facelift over break

KUIT is nearing completion on a server-move and client updates.

/news/2011/jan/07/-campus-e-mail-gets-facelift-over-break/

Financial aid office apologizes; plans new e-mailing ...

/news/2005/jun/27/e_mail/

KU Safety Office investigates fake classified ad

An ad that has appeared in The University Daily Kansan may leave ...

/news/2008/nov/13/ku_safety_office_investigates_fake_classified_ad/

University promotes students’ cyber security

KU Information Technology is encouraging students to recognize and protect themselves from ...

/news/2009/oct/21/university-promotes-cyber-security/

/comments/cr/33/7138/#c2547

Students can now get transcripts online

Registrar’s Office now allows for students to request and obtain their transcripts ...

/news/2009/sep/01/news_students/

/photos/2010/feb/03/9254/

University warns students about phone scam

Someone posing as a KU employee has reportedly been calling students and ...

/news/2008/oct/01/vishing/

Emails lost due to incorrect labeling

Last night two of the spam/virus servers for the University experienced a ...

/news/2011/mar/02/email-users-lose-messages-due-it-problem/

Expanded inboxes to allow more e-mails

Last Wednesday, Information Services announced that students’ e-mail mailboxes had been increased ...

/news/2008/feb/05/expanded_inboxes/

Outlook accounts may feature Gmail technology

The application could provide a new format and more space, but KU ...

/news/2008/feb/26/outlook_accounts/

Students suspect facebook.com monitored by schools, police

/news/2006/jan/25/facebook/

University begins investigation into record release

Leaked documents included social security cards, phone numbers, transcripts. The University was ...

/news/2007/sep/21/records/

Keeping personal information from cyber crime

Personal information can be accessed by hackers and thieves in an instant ...

/news/2012/jan/29/keeping-personal-information-cyber-crime/

Computer glitch results in refund for Edwards ...

The University is giving the affected students a grace period before they ...

/news/2008/oct/10/refunds/

Anderson: Is our democracy healthy?

/news/2008/sep/03/anderson_our_democracy_healthy/

Survey gathers student reactions to the college ...

The survey is sent by e-mail to randomly selected students.

/news/2010/mar/08/survey-gathers-student-reactons-college-experience/

KU Information Technology promotes Hawk Drive to ...

Previously available only to faculty and staff, the service promises one gigabyte ...

/news/2010/feb/02/Hawkdrive/

Student Senate notebook

Here's what happened at the Student Senate meeting Wednesday.

/news/2008/mar/13/student_senate_notebook/

University implements communication system

The University of Kansas is working to implement Message Blox, a system ...

/news/2007/apr/20/blox/

Softball player sues University

/news/2005/oct/05/ne_softball/

University warns of possible hacking

Your name, birth date, social security number and credit card number could ...

/news/2006/jan/20/hack/

University changes to new, more secure wireless ...

Before using the new network, all users need to reconfigure their wireless ...

/news/2011/jan/25/university-changes-new-more-secure-wireless-networ/

Identity fraud, viruses prompt on-campus improvements

Millions of American adults are victims of identity fraud every year, and ...

/news/2008/apr/02/identity_fraud_viruses_prompt_campus_improvements/

Softball player files lawsuit

/news/2005/oct/03/ne_lawsuit/

Users abuse Facebook

/news/2005/feb/10/news_campus_facebook/

Mangino's University parking history

Mangino has a rough past with the University's parking department that includes ...

/news/2009/dec/04/manginos-university-parking-history/

Student Health Services has online help

New online tools help students cancel appointments as well as talk to ...

/news/2010/sep/06/student-health-services-has-online-help/

Facing the music

For 13 students sued by the music industry, the risks of illegal ...

/news/2008/apr/30/facing_music/

Students unaware of Final Four lottery

All 230 students who signed up for the student ticket lottery for ...

/news/2008/apr/03/athletics/

Personal data again left unsecured

/news/2005/dec/27/personal_data_again_left_unsecured/

A question of identity

The Comanche Nation informed KU that a professor who claims he's Comanche ...

/news/2008/may/02/question_identity/

Facebook changes come in waves

Rumors claim the site is adding a webmail service.

/news/2010/feb/08/facebook-changes/

Letter: Rally e-mail should not be called ...

/news/2008/nov/14/letter_rally/

Comments

Hiya. I thought I might post links to a few helpful articles:

We get phished so you don't have to: http://www.besekure.ku.edu/~privacy/cgi-bin/mydrupal/?q=node/87

IT Security Office alert regarding phishing e-mails: http://www.security.ku.edu/alerts/alert-viewer.jsp?id=61

How to forward spam messages: http://www.email.ku.edu/spam

Sign in to comment