Phishing - don't take the bait
You just received an email from a U of T helpdesk, or senior administrator asking you to send your password, or log into what appears to be a U of T website.
Or, have you?
Every day the U of T community experiences five to 10 successful phishing attacks.
Phishing is an attempt to extract personal information such as usernames, passwords and credit card details by nefarious means. Typically, the phishing expedition comes in the form of an email that looks as though it is from a reputable organization such as a bank, a U of T helpdesk or a university network administrator.
In email the basic rule is never - under any circumstances - send your password to anyone. Even if it’s somebody you know.
“It is never appropriate to send your password through email,” said Alex Nishri, manager of integrated client services in Information + Technology Services (ITS).
Some of the phishing emails sound very good, often employing scare tactics to force recipients to act. For example, the threat of losing an email account during server maintenance. Nishri said there is never a case where ITS will require passwords in order to do maintenance.
Another tactic used to gain important information is to send a link to a website that, when clicked on, opens as a legitimate looking webpage. For example, Nishri said he recently discovered a phony version of the weblogin.utoronto.ca page. However, when recipients log into the bogus page, their usernames and passwords are collected and used for wrongdoings such as sending large amounts of spam to others.
“This has already led to some destinations rejecting mail from UTORmail/UTORExchange due to the high volume of spam we send,” said Nishri.
How do you know if a web address is phony?
Look closely at the URL (the web address), if you are not familiar with the site or the URL looks suspicious Google the organization name to determine the correct web address. Some sites will have an extended validation (EV) Certificate, which tells visitors to a website that it is legitimate.
For instance, the weblogin.utoronto.ca page has an EV certificate. When you visit the page, your browser will display an encryption lock icon and uses the colour green in the web address bar in your browser. In Internet Explorer 7 the address bar is green; in Firefox the site identify button (to the left of the URL) turns green; and in Safari the site's name displays in green on the right side of the URL address field.
If you receive a suspicious email or accidently respond to a phishing scam please notify the helpdesk on your campus.
UTM help desk www.utm.utoronto.ca/index.php?id=7005
UTSC help desk webapps.utsc.utoronto.ca/ccweb … sonal_computing.html
St George help desk help.ic.utoronto.ca/index.php
Provided by University of Toronto