We want to make sure that your correct personal email address is on file so that we can verify your account when you are not on site. This is critical if you are troubleshooting Jaspernet account access remotely.
Please follow the instructions here to update your personal email address on file.
Updates and news on how technology is changing in Manhattan University.
Showing posts with label account hacks. Show all posts
Showing posts with label account hacks. Show all posts
Tuesday, January 19, 2016
Tuesday, August 4, 2015
Windows 10 Upgrade Scam Warning
According to this blog post and others like it. There are malicious emails circulating masquerading as invitations to upgrade to Windows 10. Please note that the safest way to upgrade to Windows 10 is through Windows Update. We have not received reports of Manhattan College accounts receiving these emails. We are proactively warning users to be cautious should they receive and email as described in this blog post.
Labels:
account hacks,
alerts,
hack,
hacks,
Malware Alert,
upgrade,
warning
Thursday, November 6, 2014
Phishing attacks on the Rise
Manhattan College ITS has seen a rising trend in the number and complexity of phishing attacks reported. To raise awareness of this alarming trend, the following information is being reposted from the Google Online Security Blog.
A recent poll in the U.S. showed that more people are concerned about being hacked than having their house robbed. That’s why we continue to work hard to keep Google accounts secure. Our defenses keep most bad actors out, and we’ve reduced hijackings by more than 99% over the last few years.
We monitor many potential threats, from mass hijackings (typically used to send lots of spam) to state-sponsored attacks (highly targeted, often with political motivations).
This week, we’re releasing a study of another kind of threat we’ve dubbed “manual hijacking,” in which professional attackers spend considerable time exploiting a single victim’s account, often causing financial losses. Even though they’re rare—9 incidents per million users per day—they’re often severe, and studying this type of hijacker has helped us improve our defenses against all types of hijacking.
Manual hijackers often get into accounts through phishing: sending deceptive messages meant to trick you into handing over your username, password, and other personal info. For this study, we analyzed several sources of phishing messages and websites, observing both how hijackers operate and what sensitive information they seek out once they gain control of an account. Here are some of our findings:
We’ve used the findings from this study, along with our ongoing research efforts, to improve the many account security systems we have in place. But we can use your help too.
Take a few minutes and visit the Secure Your Account page, where you can make sure we’ve got backup contact info for you and confirm that your other security settings are up to date.
A recent poll in the U.S. showed that more people are concerned about being hacked than having their house robbed. That’s why we continue to work hard to keep Google accounts secure. Our defenses keep most bad actors out, and we’ve reduced hijackings by more than 99% over the last few years.
We monitor many potential threats, from mass hijackings (typically used to send lots of spam) to state-sponsored attacks (highly targeted, often with political motivations).
This week, we’re releasing a study of another kind of threat we’ve dubbed “manual hijacking,” in which professional attackers spend considerable time exploiting a single victim’s account, often causing financial losses. Even though they’re rare—9 incidents per million users per day—they’re often severe, and studying this type of hijacker has helped us improve our defenses against all types of hijacking.
Manual hijackers often get into accounts through phishing: sending deceptive messages meant to trick you into handing over your username, password, and other personal info. For this study, we analyzed several sources of phishing messages and websites, observing both how hijackers operate and what sensitive information they seek out once they gain control of an account. Here are some of our findings:
- Simple but dangerous: Most of us think we’re too smart to fall for phishing, but our research found some fake websites worked a whopping 45% of the time. On average, people visiting the fake pages submitted their info 14% of the time, and even the most obviously fake sites still managed to deceive 3% of people. Considering that an attacker can send out millions of messages, these success rates are nothing to sneeze at.
- Quick and thorough: Around 20% of hijacked accounts are accessed within 30 minutes of a hacker obtaining the login info. Once they’ve broken into an account they want to exploit, hijackers spend more than 20 minutes inside, often changing the password to lock out the true owner, searching for other account details (like your bank, or social media accounts), and scamming new victims.
- Personalized and targeted: Hijackers then send phishing emails from the victim’s account to everyone in his or her address book. Since your friends and family think the email comes from you, these emails can be very effective. People in the contact list of hijacked accounts are 36 times more likely to be hijacked themselves.
- Learning fast: Hijackers quickly change their tactics to adapt to new security measures. For example, after we started asking people to answer questions (like “which city do you login from most often?”) when logging in from a suspicious location or device, hijackers almost immediately started phishing for the answers.
- Stay vigilant: Gmail blocks the vast majority of spam and phishing emails, but be wary of messages asking for login information or other personal data. Never reply to these messages; instead, report them to us. When in doubt, visit websites directly (not through a link in an email) to review or update account information.
- Get your account back fast: If your account is ever at risk, it’s important that we have a way to get in touch with you and confirm your ownership. That’s why we strongly recommend you provide a backup phone number or a secondary email address (but make sure that email account uses a strong password and is kept up to date so it’s not released due to inactivity).
- 2-step verification: Our free 2-step verification service provides an extra layer of security against all types of account hijacking. In addition to your password, you’ll use your phone to prove you’re really you. We also recently added an option to log in with a physical USB device.
Take a few minutes and visit the Secure Your Account page, where you can make sure we’ve got backup contact info for you and confirm that your other security settings are up to date.
Posted by Elie Bursztein, Anti-Abuse Research Lead
Reposted from the Google Online Security Blog: http://googleonlinesecurity.blogspot.com/2014/11/behind-enemy-lines-in-our-war-against.html
Friday, April 11, 2014
Heartbleed Bug
The following is an update to the Manhattan College community regarding the recently discovered Heartbleed software bug - http://heartbleed.com/
ITS has been working with our software vendors to investigate our exposure to the recently identified Heartbleed bug that affects OpenSSL software - one of the most common cryptographic libraries used to secure Internet communications such as secure websites (via https://) and VPNs.
The majority of our "production" systems such as www.manhattan.edu, Banner, self-service, SSO, Moodle, etc were never vulnerable to the flaw based on the version of software installed on these systems. Some "test" systems with limited access were vulnerable, but patched by Tuesday AM. Additionally, ITS is taking preventative measures to update software and configurations on all systems running OpenSSL cryptographic software as a precaution.
What do I need to do? Be aware of scams!
In the coming days, you may be notified by various services related to your social media, banking, or other accounts potentially affected by the Heartbleed bug. Take these notifications seriously and consider changing your password on these services. Currently, no action is required for your JasperNet account. If this changes, the campus community will be notified.
Be aware of scams! With the legitimate notices will come "phishing" scams from illegitimate sources asking for your username, password and/or other personal information. ALWAYS verify the legitimacy of these types of messages and NEVER give your password or personal information unless you are certain that you are dealing with a trusted service. Tips on how to avoid phishing scams can be found here: http://www.phishing.org/scams/prevent-phishing/
ITS has been working with our software vendors to investigate our exposure to the recently identified Heartbleed bug that affects OpenSSL software - one of the most common cryptographic libraries used to secure Internet communications such as secure websites (via https://) and VPNs.
The majority of our "production" systems such as www.manhattan.edu, Banner, self-service, SSO, Moodle, etc were never vulnerable to the flaw based on the version of software installed on these systems. Some "test" systems with limited access were vulnerable, but patched by Tuesday AM. Additionally, ITS is taking preventative measures to update software and configurations on all systems running OpenSSL cryptographic software as a precaution.
What do I need to do? Be aware of scams!
In the coming days, you may be notified by various services related to your social media, banking, or other accounts potentially affected by the Heartbleed bug. Take these notifications seriously and consider changing your password on these services. Currently, no action is required for your JasperNet account. If this changes, the campus community will be notified.
Be aware of scams! With the legitimate notices will come "phishing" scams from illegitimate sources asking for your username, password and/or other personal information. ALWAYS verify the legitimacy of these types of messages and NEVER give your password or personal information unless you are certain that you are dealing with a trusted service. Tips on how to avoid phishing scams can be found here: http://www.phishing.org/scams/prevent-phishing/
Labels:
account hacks,
Banner,
Calendar,
Gmail,
Google Apps,
Google Calendar,
Google Drive,
Google Groups,
hack,
hacks,
phishing,
scam,
warning,
web
Monday, March 24, 2014
Gmail Account Hacks and Checking Account Activity

"Last account activity", a very useful feature of Google mail, shows you information about recent activity with your account. This information is extremely useful for detecting or verifying unauthorized access to your email account. Critical information about each time you account was accessed, including time and IP address, is available with "last account activity".
Click here for detailed instructions on accessing and using the information made available by "last account activity".
Remember, Manhattan College ITS will never ask for your password or other personal information via email. Messages requesting such information are fraudulent and should be deleted. If you detect suspicious activity in your email account you should change your password immediately at https://start.manhattan.edu/changepassword/login. We recommend changing your password periodically to prevent fraudulent activity.
Labels:
account hacks,
Gmail,
hack,
hacks,
last account activity
Subscribe to:
Posts (Atom)

