Showing posts with label cyber security awareness. Show all posts
Showing posts with label cyber security awareness. Show all posts

Wednesday, December 20, 2023

Foundational Cyber Security Awareness Course

A short foundational cyber security awareness course open to all members of the Manhattan College community

This course can be completed in under ten minutes and will guide you through how to identify and respond to the most common phishing attacks.

Do you focus your thoughts on creative solutions? Do you work well with others? Are you results-oriented?

Malicious criminals who use phishing tactics hope you are and to use your behavior against you. Please use care for your welfare and talk to your loved ones for their benefit of their welfare.

Monday, November 29, 2021

New Cyber Security Requirements

As you surely have seen in the news or in your personal life recently, cyber attacks continue to develop and increase in frequency and complexity.  Many organizations - including major technology and social media companies - are taking additional steps to ensure that the accounts of their employees and customers remain well-protected.  Manhattan College has not been immune to these attacks and associated risks and we are now being required to implement stricter controls for our community members who access institutional data.  Given this new reality, two specific requirements that we must meet are as follows:

  • All Employees must complete a yearly Cyber Security training program (More information will be coming about this shortly. This must be completed by January 21, 2022)

  • All Employees must enroll their JasperNet account in Multi-Factor Authentication (MFA or 2SV) (Must be completed by January 18th, 2022 or you will be auto-enrolled)


Cyber Security Training

ITS is actively working with our insurance provider to develop a yearly Cyber Security training program that must be completed on a yearly basis starting in January 2022.  More information about the cyber security training program will be made available in the new year and must be completed by December 31st each year.  Content for the initial training program will be delivered by our insurance provider, however, we will assess the program throughout the year and provide the opportunity for campus experts to participate in determining and developing the curriculum for following years in alignment with the same requirements of the insurance provider.  ALL employees (including Faculty, Graduate Assistants, and Student Employees) will be required to complete this course yearly.


Multi-Factor Authentication

Multi-Factor Authentication (MFA) - sometimes referred to as Two-Step Verification (2SV) - will be required for all employees going forward and must be implemented no later than January 2022.  While Manhattan College has previously taken a very targeted and calculated approach to require MFA based on a “risk score” (i.e. users that access Banner or other escalated access), we must now require MFA for ALL employees (including Faculty, Graduate Assistants, and Student Employees).  To date, over 670 community members have already enrolled in MFA.  ITS will be contacting community members that still need to enroll in MFA in the coming days to provide instructions and support for enabling MFA by 1/18/2022.


MFA Support Sessions


ITS will be offering support sessions with members from the Technology Training team for those who will need to enable DUO Multi-Factor Authentication on their JasperNet accounts. Below please find more information about the drop-in training sessions. There is no signup required.

When:

  • January: 12th, 18th, and 19th (all Wednesday’s) from 11:00am-2:00pm


Where: MGL 305 (Computer Lab)

Please remember to bring your cell phone to complete the setup.

If you are unable to attend or have any questions please contact its@mahattan.edu and someone from the Training Team will reach out to schedule a separate time and answer any questions you may have.


Wednesday, October 6, 2021

Phishing Campaign -- $1,499 iCloud Orders

Today multiple gmail.com accounts sent emails to a fraction of our organization. The emails claim that the recipient would be charged $1,499 for their 12TB iCloud storage plan.

This is a good opportunity to announce that October is Cyber Security Awareness month. Best to keep in mind that any email may be a scam and we all are one degree away from criminals.

The most common IT crime still is Business Email Compromise (BEC) even though ransomware is increasing rapidly. It is best to be mindful of how to parse an email address and to do your best to understand who is emailing you.

Email addresses are formed by concatenating a username with the '@' sign and with a domain (e.g., bob@example.com). Sometimes people are confused by the common phishing addresses that use a domain inside the username (e.g., bob.manhattan.edu@example.com). Understand that such email addresses are available to anyone including to criminals.

If you receive a phishing email, you can report it to Gmail if you're using the web interface (not the Gmail mobile app, unfortunately). Google will alert ITS!

Gmail's 'Report phishing' feature is under a vertical ellipsis in the upper-right of an email.

You can also forward the email to its@manhattan.edu. If you are unsure if an email is a phishing email, please forward it to its@manhattan.edu. We can help to determine what is what and if necessary report the email as a phishing attempt to Google.

Monday, September 20, 2021

Cyber Security: What is it?

As we make our way into the future, the world becoming more digital by the day, it is important we are all cyber aware and understand the meaning of cyber security. In an article written by Sharon Shea, cyber security is explained to be “the protection of internet-connected systems such as hardware, software and data from cyberthreats”. Cyber security is broken up into many sections including:

  • Data security 

  • Network security 

  • Cloud security 

All sections are important to the success of a cyber security program.


Cyber security’s importance increases as the number of users, devices and programs continue to increase as well. This forces us to learn the threats that we are being exposed to everyday and how we can prevent them. Some threats include:

  • Malware

  • Social engineering

  • Phishing 

By keeping up with the changing risks, we can make our own changes as simple as enabling a firewall or making complex and unique passwords for your different accounts. There are several tips you can follow including the ones in this blog post


With our growing cyber awareness, the need for professionals in the field also grows. Cyber security comes with multiple opportunities to start a career. Some security roles include:

  • Security engineers

  • Security Architects

  • Security Analysts

Many other career paths are available within the field of cyber security and are in demand. The industry is in high demand for professionals who can fulfill such roles. 


The growth of cyber security comes with knowledge we should all be aware of, including the risks, preventative measures, and the job opportunities it opens. Cyber security is taking on the world at an increasing pace. 


Source: Shea, Sharon, et al. “What Is Cybersecurity? Everything You Need to Know.” SearchSecurity, TechTarget, 25 May 2021, searchsecurity.techtarget.com/definition/cybersecurity. 




Wednesday, April 28, 2021

Phishing Security Refresher

Cyber security is the practice of protecting computers, servers, mobile devices, electronic systems, networks, and data from attacks. These cyberattacks are usually aimed towards destroying sensitive information, extorting money from users, or interrupting normal business processes.


Phishing is the practice of sending fraudulent emails that resemble emails from reputable sources. The aim is to steal sensitive data like credit card numbers and login information. It’s the most common type of cyber attack.


Phishing attacks are designed to trick users into taking actions that are not in their best interests. They can be avoided by doing the following:

  • Verify message sender

  • Before clicking a link, verify that it goes to where it claims by hovering over it and checking the destination URL and browse to the target site directly in your browser.

  • Be cautious of attachments. Do not open a file that you’re not expecting.

  • Don’t enter your credentials into a site that you do not recognize.

  • Create a SPAM filter that detects viruses and blank senders.

Friendly Reminders:

  • You should always inform ITS of any suspicious emails you receive but when in doubt, forward the email in question to its@manhattan.edu so we can verify

  • If you would like help setting up filters in your email you can use this link to put in a service request and a member of our Training Team will schedule a 1:1 appointment with you. 

For more information please check out this article


Tuesday, February 23, 2021

What is Ransomware & How Can You Protect Yourself From It?

Ransomware is a class of malware that prevents you from accessing your systems or data and demands a sum of money to be paid in return for the decryption key. This has resulted in billions of dollars in losses with over 2 million incidents reported in 2019. These kinds of cyberattacks are getting more complex and are holding organizations hostage until they pay millions in ransom. Ransomware attacks have a new target every 14 seconds and have the ability to shutdown digital operations, steal information, and exploit businesses, essential services, and individuals. 


Below are precautions to protect you against the threat of ransomware:
  • Update software and operating systems. Outdated applications and operating systems are the target of most attacks.

  • Never click on links or open attachments in unsolicited emails.

  • Backup data on a regular basis. Keep it on a separate device and store it offline.

  • Restrict permissions to install and run software applications.

  • Enable strong spam filters to prevent phishing emails from reaching you and authenticate inbound email to prevent email spoofing.

  • Scan all incoming and outgoing emails to detect threats.

  • Configure firewalls to block access to known malicious IP addresses.

For more information on Ransomware and how to defend against it please check out these articles: 

Sunday, November 10, 2019

How Can Higher Ed Better Prepare Cybersecurity Students for a Hot Job Market?

The 2018 (ISC)2 Cybersecurity Workforce Study estimates a global shortage of cybersecurity professionals of around three million workers. This shortage of skilled job seekers is having a real-world impact on companies and the people responsible for cybersecurity at those companies. The study also points out that Gen X and Baby Boomer workers make up about half of the current cybersecurity workforce, leaving many entry-level opportunities for new college graduates and pathways for growth as these more experienced workers approach retirement age.

The need for trained cybersecurity professionals is not going to go away. The US Bureau of Labor Statistics projects a 28% growth in US employment for cybersecurity consultants between 2016 and 2026. How can we help our students go beyond the theoretical concepts taught in computer science or cybersecurity classes and make themselves more attractive to future employers? We need to take the lead to encourage students to take the initiative to learn more about current issues in cybersecurity and take advantage of the many cybersecurity resources available.
Here are some ways you can help your students and contribute to narrowing the cybersecurity skills gap:
  • Hold informational sessions on cybersecurity. Help spread the word on your campus about the cybersecurity skills gap and job opportunities. You could ask your CISO or information security team to conduct a cybersecurity seminar or invite local experts to share their knowledge and expertise with your students. The Enterprise Security Team at The Ohio State University has already implemented this idea, and they sponsor an annual and free on-campus Cybersecurity Days to expand knowledge of security and data protection for their entire college community.
  • Sponsor or encourage membership in student associations. There are two student cybersecurity organizations for your students to explore—NationalCybersecurity Student Association and Women in CyberSecurity (WiCyS. The National Cybersecurity Student Association has a number of resources on their website, and you can sign up for their newsletter or follow their Snapchat account to view a day in the life of a cyber student or industry professional. The WiCyS is dedicated to bringing together women in cybersecurity from academia, research, and industry to share knowledge, experience, networking, and mentoring. You can also explore setting up a local WiCyS student chapter on your campus.
  • Offer campus internships. In addition to knowledge of advanced cybersecurity concepts, the most important qualification for cybersecurity employment is relevant work experience. You can help your students by hiring them as interns in your institution's information security department. This offers students real-world experience while providing supplemental staffing for your department. For suggested qualifications and responsibilities, use the Information Security Intern Job Description Template on the EDUCAUSE website as a starting point.
  • Identify scholarship opportunities. The CyberCorps: Scholarship for Services, funded by the NSF, provides up to $22,500 per year for undergraduates and $34,000 per year for graduate students. In return, students commit to work in a for a federal, state, or local agency for a period matching the length of their scholarship. The Cyber Security Degree website provides a comprehensive list of additional cybersecurity scholarships and other career resources.
  • Encourage students to deepen their knowledge. The NICCS Education Training Catalog is a central location where cybersecurity professionals across the nation can find more than 3,000 cybersecurity-related courses. Anyone can use the interactive map and filters to search for courses offered in their local area to add to their skill set, increase their level of expertise, or earn a certification. You could also direct your students to take advantage of the free online courses offered through edXUS Department of Homeland Security, Cybrar, or SANS Cyber Aces Online.
  • Attend cyber competitions. Institutions with an information assurance or computer security curriculum can give their students an additional way to hone their skills and have fun by participating in regional events hosted by the National Collegiate Cyber Defense Competition(NCCDC). The top regional teams can then go on to the National Championship, which was won by University of Virginia in 2018. Another cybersecurity competition for high school and college students is the National Cyber League (NCL), is a defensive and offensive puzzle-based, capture-the-flag style competition. All participants play the games simultaneously and are tested with real cybersecurity challenges they will likely face in the workforce.
  • Participate in cybersecurity conferences. Students may be interested the educational and networking opportunities from attending the annual conferences for the National Cybersecurity Student Association or Women in CyberSecurity. For additional conferences in your area, InfoSec publishes a comprehensive list with hundreds of cybersecurity events in the United States, Europe, and Asia.

Sunday, October 27, 2019

Top Tips to Securely Using Social Media


Manhattan College IT Services is sharing cyber safety tips in support of raising awareness during National Cyber Security Awareness Month, October 2019.

Overview 

Social media sites, such as Snapchat, Facebook, Twitter, Instagram, and LinkedIn, are amazing resources, allowing you to meet, interact, and share with people around the world. However, with all this power comes risks--not just for you, but your family, friends, and employer. In this post, we cover the key steps to making the most of social media securely and safely. 

Posting 

Be careful and think before posting. Anything you post will most likely become public at some point, impacting your reputation and future, including where you can go to school or the jobs you can get. If you don’t want your family or boss to see it, you probably shouldn’t post it. Also, be aware of what others are posting about you. You may have to ask others to remove what they share about you. 

Privacy 

Almost all social media sites have strong privacy options. Enable them when possible. For example, does the site really need to be able to track your location? In addition, privacy options can be confusing and change often. Make it a habit to check and confirm they are working as you expect them to. 

Passphrase 

Secure your social media account with a long, unique passphrase. A passphrase is a password made up of multiple words, making it easy for you to type and remember, but hard for cyber attackers to guess. 

Lock Down Your Account 

Even better, enable two-factor authentication on all of your accounts. This adds a one-time code with your password when you need to log in to your account. This is actually very simple and is one of the most powerful ways to secure your account. 

Scams 

Just like in email, bad guys will attempt to trick or fool you using social media messages. For example, they may try to trick you out of your password or credit card. Be careful what you click on: If a friend sends you what appears to be an odd message or one that does not sound like them, it could be a cyber attacker pretending to be your friend. 

Terms of Services

Know the site’s terms of service. Anything you post or upload might become the property of the site.

Work

If you want to post anything about work, check with your supervisor first to make sure it is okay to publicly share.
Follow these tips to enjoy a much safer online experience. To learn more on how to use social media sites safely, or report unauthorized activity, check your social media site’s security page.


Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

Refer to Manhattan College's Email Signature Knowledge Base 
Article for instructions on how to create your own email signature. 
Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

Reach out to IT Services with any questions:



Partially reposted from www.sans.org/security-awareness


Sunday, October 20, 2019

Cyber World Reality Facts


sobering cyber stats

millenials often fall victim to cybercrime
  1. Microsoft Security Intelligence Report and Consumer Reports
  2. AARP, “Caught in the Scammer’s Net: Risk Factors That May Lead to Becoming an Internet Fraud Victim,” 2014
  3. Norton Cyber Security Insights Report Q1, 2017
  4. Ponemon Institute, “2015 Cost of Cyber Crime Study: Global,” 2015
  5. Facebook
  6. Federal Trade Commission, “The Top Frauds of 2017”
  7. staysafeonline.org

For more information on this topic review The Facts Get Clued into the Cyber World Reality.

Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.



Refer to Manhattan College's Email Signature Knowledge Base 
Article for instructions on how to create your own email signature. 
Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

Reach out to IT Services with any questions:


Sunday, October 6, 2019

Stop That Phish

Overview




phishing computer screen

Email and messaging services (such as Skype, Twitter, or Snapchat) are one of the primary ways we communicate. We not only use these technologies every day for work, but also to stay in touch with friends and family. Since so many people around the world depend on these technologies, they have become one of the primary attack methods used by cyber attackers. This attack method is called phishing. Learn what phishing is and how you can spot and stop these attacks, regardless if you are at work or at home.

What Is Phishing

Phishing is a type of attack that uses email or a messaging service to fool you into taking an action you should not take, such as clicking on a malicious link, sharing your password, or opening an infected email attachment. Attackers work hard to make these messages convincing and tap your emotional triggers, such as urgency or curiosity. They can make them look like they came from someone or something you know, such as a friend or a trusted company you frequently use. They could even add logos of your bank or forge the email address so the message appears more legitimate. Attackers then send these messages to millions of people. They do not know who will take the bait, all they know is the more they send, the more people will fall victim.

Protecting Yourself

In almost all cases, opening and reading an email or message is fine. For a phishing attack to work, the bad guys need to trick you into doing something. Fortunately, there are clues that a message is an attack. Here are the most common ones:
  • A tremendous sense of urgency that demands “immediate action” before something bad happens, like threatening to close an account or send you to jail. The attacker wants to rush you into making a mistake.
     
  • Pressuring you to bypass or ignore your policies or procedures at work.
     
  • A strong sense of curiosity or something that is too good to be true. (No, you did not win the lottery.)
     
  • A generic salutation like “Dear Customer.” Most companies or friends contacting you know your name.
     
  • Requesting highly sensitive information, such as your credit card number, password, or any other information that a legitimate sender should already know.
     
  • The message says it comes from an official organization, but has poor grammar or spelling or uses a personal email address like @gmail.com.
     
  • The message comes from an official email (such as your boss) but has a Reply-To address going to someone’s personal email account.
     
  • You receive a message from someone you know, but the tone or wording just does not sound like him or her. If you are suspicious, call the sender to verify they sent it. It is easy for a cyber attacker to create a message that appears to be from a friend or coworker.
Ultimately, common sense is your best defense. If an email or message seems odd, suspicious, or too good to be true, it may be a phishing attack. 
Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

Refer to Manhattan College's Email Signature Knowledge Base 
Article for instructions on how to create your own email signature.

Using a Manhattan College email signature is important because it is the perfect opportunity to brand every message you send. By creating a cohesive email signature for each employee on your team, you create brand recognition in every person to whom your employees sends emails. 

Reach out to IT Services with any questions:


Tuesday, August 20, 2019

Understanding the Basics of Online Safety and Security

Americans use 3,138,420 GB of internet data every minute of the day. It is safe to say that being online is now a way of life for many. Engaging in safe and secure online practices helps protect against the risks of living life on the internet.
Shopping, surfing, banking, gaming, and connecting Internet of Things devices such as toasters and refrigerators are some of the many actions performed each minute in cyberspace. These common everyday activities carry the cyber threats of social engineering to gain unauthorized access to data, identity theft, bullying, location tracking, and phishing, to name just a few. How can we decrease our risk from these cyber threats without abandoning our online activities altogether? Here are some basic online tips everyone can follow to help stay secure while online.


  • Set up alerts. Consider setting up alerts on your financial accounts. Many credit card companies and banks allow you to set up alerts on your accounts via their websites. These alerts range from sending you an email or text each time a transaction happens on your account to alerts when transactions meet or exceed a designated spending limit that you set. These alerts keep you in control of your accounts' activities. These types of alerts are useful because they make you aware of what's going on with your account quicker than waiting for monthly statements. When you receive an alert about a transaction that you did not authorize, you can reach out to the credit card company or bank immediately. Log into your credit card company and banking websites to set up alerts on your accounts.
  • Keep devices and apps up to date. This familiar tip is useful even if you are just casually surfing the internet. Keeping your devices up to date (including apps and operating systems) ensures you have the latest security fixes.
  • Don't use public Wi-Fi. In addition to an updated device, the network the device is connected to is also important. Did you have to enter a password to connect to a Wi-Fi network? If you did, that network is more secure than an open one that any device within range can connect to. Whenever possible, use a secure network, especially when banking or shopping online.
  • Consider using a VPN. VPN stands for virtual private network, and its main purpose is to provide a tunnel for encrypted internet traffic. If you are connected to the internet without using a VPN, your traffic is passed through the internet service provider's servers. The location of your device is known, and if you must connect to a public Wi-Fi network, there is a risk of snooping by other devices on the same network. Connecting to a VPN redirects your internet traffic to a remote server, encrypting the traffic, reducing the snooping risk. There are many options for VPN software today for consumers and businesses. Do your research and decide which one makes sense for your online needs.
  • Create unique passwords. Here's another familiar tip. Using the same password for many sites is not a best practice. Suppose that one of your accounts suffered a data breach and your password was exposed. If you reused this password on other accounts, it's likely that someone would be able to access those accounts as well (especially if your user name is an email address). Consider using a password manager to manage all your passwords. Not only do these tools manage all your passwords, they can also create strong passwords and can even autofill your username and password as you go to websites on different browsers.
  • Be vigilant. Be aware, there are fake websites out there waiting to collect your valuable information. Make sure you are on a legitimate site by double-checking the URL website address to make sure it is spelled correctly. Also make sure you see a padlock and https:// in the URL.
Remember that you are in control of your online activities. Following these security tips will give you peace of mind while online.

Be Secure Online! Refer to Manhattan College's Cyber Safety site for additional resources.

Refer to Manhattan College's Email Signature Knowledge Base Article for instructions on how to create your own email signature.

Wednesday, May 8, 2019

Cryptocurrencies - Look Before You Leap!

image of a gold bitcoin


Cryptocurrency comes under many names. You have probably read about some of the most popular types of cryptocurrencies such as Bitcoin, Litecoin, and Ethereum. Cryptocurrencies are increasingly popular alternatives for online payments. Before converting real dollars, euros, pounds, or other traditional currencies into ₿ (the symbol for Bitcoin, the most popular cryptocurrency), you should understand what cryptocurrencies are, what the risks are in using cryptocurrencies, and how to protect your investment.
What is cryptocurrency? A cryptocurrency is a digital currency, which is an alternative form of payment created using encryption algorithms. The use of encryption technologies means that cryptocurrencies function both as a currency and as a virtual accounting system. To use cryptocurrencies, you need a cryptocurrency wallet. These wallets can be software that is a cloud-based service or is stored on your computer or on your mobile device. The wallets are the tool through which you store your encryption keys that confirm your identity and link to your cryptocurrency.
What are the risks to using cryptocurrency? Cryptocurrencies are still relatively new, and the market for these digital currencies is very volatile. Since cryptocurrencies don't need banks or any other third party to regulate them; they tend to be uninsured and are hard to convert into a form of tangible currency (such as US dollars or euros.) In addition, since cryptocurrencies are technology-based intangible assets, they can be hacked like any other intangible technology asset. Finally, since you store your cryptocurrencies in a digital wallet, if you lose your wallet (or access to it or to wallet backups), you have lost your entire cryptocurrency investment.
Follow these tips to protect your cryptocurrencies:
  • Look before you leap! Before investing in a cryptocurrency, be sure you understand how it works, where it can be used, and how to exchange it. Read the webpages for the currency itself (such as Ethereum, Litecoin, Bitcoin) so that you fully understand how it works, and read independent articles on the cryptocurrencies you are considering as well.
  • Use a trustworthy wallet. It is going to take some research on your part to choose the right wallet for your needs. If you choose to manage your cryptocurrency wallet with a local application on your computer or mobile device, then you will need to protect this wallet at a level consistent with your investment. Just like you wouldn't carry a million dollars around in a paper bag, don't choose an unknown or lesser-known wallet to protect your cryptocurrency. You want to make sure that you use a trustworthy wallet.
  • Have a backup strategy. Think about what happens if your computer or mobile device (or wherever you store your wallet) is lost or stolen or if you don't otherwise have access to it. Without a backup strategy, you will have no way of getting your cryptocurrency back, and you could lose your investment.
What is Cryptocurrency?



    This Quadrangle article: Group of Students Create ‘MunchCoin,’ A Cryptocurrency For Local Eateries describes how several of our Manhattan College engineering and business students independently started their own cryptocurrency company in our neighborhood restaurants.  Note that among the students who created this cryptocurrency are several IT student workers and 1 full time ITS employee. 
    The story is impressive for several reasons, the students were able to : 

    • Put their engineering and data analysis skills into practice.  
    • Successfully navigate the cryptocurrency emerging technology. 



    Partially reposted from:  Educause's Campus Security Awareness Campaign  Cryptocurrencies - Look Before You Leap!

    Tuesday, April 9, 2019

    Whaling, SMiShing, and Vishing…Oh My!


    credit card with fish hook speared through it


    Cybercriminals use types of social engineering—manipulating people into doing what they want—as the most common way to steal information and money. Social engineering is at the heart of all types of phishing attacks—those conducted via email, SMS, and phone calls. Technology makes these sorts of attacks easy and very low risk for the attacker. Make sure you're on the lookout for these variants on the traditional, mass emailed phishing attack.
    • Spear phishing: This kind of attack involves often very well-crafted messages that come from what looks like a trusted VIP source, often in a hurry, targeting those who can conduct financial transactions on behalf of your organization (sometimes called "whaling").
    • SMiShing: Literally, phishing attacks via SMS, these scams attempt to trick users into supplying content or clicking on links in SMS messages on their mobile devices. Flaws in how caller ID and phone number verification work make this an increasingly popular attack that is hard to stop.
    • Vishing: Voice phishing, these are calls from attackers claiming to be government agencies such as the IRS, software vendors like Microsoft, or services offering to help with benefits or credit card rates. Attackers will often appear to be calling from a local number close to yours. As with SMiShing, flaws in how caller ID and phone number verification work make this a dangerous attack vector.
    No matter the medium, follow these techniques to help prevent getting tricked by these social engineering attacks:
    • Don't react to scare tactics: All of these attacks depend on scaring the recipient, such as with a lawsuit, that their computer is full of viruses, or that they might miss out on a chance at a great interest rate. Don't fall for it!
    • Verify contacts independently: Financial transactions should always follow a defined set of procedures, which includes a way to verify legitimacy outside email or an inbound phone call. Legitimate companies and service providers will give you a real business address and a way for you to contact them back, which you can independently verify on a company website, support line, etc. Don't trust people who contact you out of the blue claiming to represent your company.
    • Know the signs: Does the message/phone call start with a vague information, a generic company name like "card services," an urgent request, and/or an offer that seems impossibly good? Hang up or click that delete button!
    For further information on how a phishing attack affected this undergraduate students view this video:




    Information Security Awareness Training Video: "Phishing: E-Safe"


    View this video for strategies on how to address illegal robocalls:

    FCC Chairman provides some tips to help consumers confront illegal robocalls and maliciously spoofed calls.

    Partially reposted from: Educause Campus Security Awareness Campaign 2019: April 2019: Whaling, SMiShing, and Vishing…Oh My!

    Monday, February 11, 2019

    How to Use Social Media for Good—Safely Creating a Positive Presence Online

    Our social networks tell a story about us. You want to make sure that the story your social media tells about you is a good one. As articulated in a blog from the the Digital Marketing Institute: "Sharing online allows you to craft an online persona that reflects your personal values and professional skills. Even if you only use social media occasionally, the content you create, share, or react to feeds into this public narrative. How you conduct yourself online is now just as important as your behavior offline."
    A positive online reputation is vital in today's digital world. Like it or not, your information is out there. What you can do is help to control it and what it says about you.
    Social media is so ingrained in our society that almost everyone is connected to it in some form. With every social media account you sign up for, every picture you share, and every post you make, you are sharing information about yourself with not only your friends and family but the entire digital world. How can you make sure your information and reputation stay safe online? Here are a few easy steps to get you started.
    • Keep it clean and positive. Be entirely sure about what you're posting. Make sure to post content that you feel positively reflects you, your creativity, your values, and your skills. Remember that future employers may look at your social media accounts before hiring you. Questionable content can leave a bad impression; this can include pictures, videos, or even opinions that make you seem unprofessional or mean and may end up damaging your reputation.
      Always think before you post or share negative or inappropriate content. Use the 24-hour rule before posting, allowing yourself 24 hours before posting any content that may be questionable to give yourself time to reflect on whether it is a good idea.
    • Oversharing and geotagging. Never click and tell. It can seem like everyone posts personal information on social media all the time, including where they are and where they live. As noted on the DHS.gov site: "What many people don't realize is that these seemingly random details are all criminals need to know to target you, your loved ones, and even your physical belongings—online and in the real world. Avoid posting names, phone numbers, addresses, school and work locations, and other sensitive information (whether it's in the text or in the photo you took). Disable geotagging, which allows anyone to see where you are—and where you aren't—at any given time."
      If you really want to post that picture of your friends at brunch, consider following the concept of #latergram and post your content at a later time than when it actually happened. It is a win-win. You get to share your experience and at the same time still maintain the privacy of your location in real time.
    • Don't rely on privacy settings. You have a private social media account so you can post anything you want? Nope. Privacy settings make it harder to see your full account, but it's not impossible. Also, there is always the chance that one of the people with access to your private account could screenshot and share the content.
      Make sure to keep your social media apps up to date and check the privacy settings frequently. Under no circumstances should you rely on privacy settings to shield inappropriate content. If there is any question that the content is inappropriate, don't post it.
    • Make sure you're professional. Keep it classy! Every post is a reflection of you. Your social media accounts allow you to put your best foot forward or stumble if you aren't careful. A positive social media presence can help create both personal and professional opportunities. Promote your personal brand or what you want people to think of you. And, your high school English teacher was correct—proper spelling and grammar are always a plus.
    • Control your content. Claim your identity on social media. Set up social media accounts and keep the profiles current. You don't have to join every platform; a few key ones will do. You can also look into apps that will cross post the content to all of your social media accounts, freeing up some of your valuable time. Use your accounts to engage professionally and personally in a positive way.
      Your social media accounts should tell the story of you that you want employers and others to see. Google your own name on a regular basis to make sure that that information out there is accurate. If you find incorrect information online, request that the website update it or take it down.
    If you follow these few simple recommendations, you are on your way to safely building a positive online reputation. Using social media positively doesn't mean you can't have fun and use it to express yourself; however, you want to ensure that you're okay with anyone seeing everything you post. Once you post something online, it's out there forever.

    Partially reposted from Educause Security Awareness Campaign 2019 Materials