Malicious emails are frequently sent to university email accounts. Such messages may contain malware or ask you to disclose sensitive data.
Personalised emails
A specific type of malicious email has been circulating for some time now. It relies on highly personalising the emails using publicly available contact details, which tricks the recipient into letting their guard down. The advice for these emails is exactly the same as for any other type of malicious email: delete them!
You can find further details in this Heise article.
Spotting malicious emails
You can identify potentially malicious emails by checking the points in the following (incomplete) list:
- cryptic combinations of characters in the email address
- the sender’s name and email address do not match
- a large number of spelling and grammatical errors
- the salutation and closing are different from the rest of the message
- File attachments with duplicate file extensions (e.g. .pdf.exe)
- Requests to enter data on third-party websites
As the details of the email sender can be chosen freely, it may appear at first glance that the email comes from a person or organisation you know. You should therefore always remain sceptical and question the intentions behind the email and its sender. The URZ only sends signed emails.
Emails containing malware
Emails containing links to malware or with malware attached are constantly in circulation. Such software can include viruses, Trojans or ransomware. The latter can pose a particular threat, as it encrypts the data on your hard drive and will only release the corresponding key in exchange for a ransom.
To help you avoid unpleasant consequences, we would like to provide you with the following guidelines:
- Always be sceptical of unexpected emails relating to invoices, job applications or correspondence from solicitors.
- Do not click on any links that lead to dubious websites. These may also include Dropbox links. Be generally sceptical in such cases.
- Do not open email attachments with the extensions “*.exe”, “*.msi” or “*.bat” (e.g. “application.pdf.exe”), and exercise caution with ZIP or RAR archives as well. This applies equally to attachments from known senders. The information contained in an email may have been tampered with. For this reason, staff at the data centre use certificates as proof of identity.
- If you receive emails with questionable content from senders you know, check with the senders or inform them that emails are being sent in their name.
- If you receive Office attachments, open them in isolated viewers (e.g. online Office viewers) within your browser. In these viewers, macros are initially disabled; macros can activate or install malware via additional source code. As a general rule, ensure you use the ‘Block macros’ setting in Office so that they are only enabled when necessary.
- Use the URZ’s central file servers to store your data. Automatic snapshots and backups are created here, enabling very quick and easy recovery of your data in the event of damage.
- Carry out regular security updates for your software, including browser plug-ins. This also applies to Mac and Linux.
Phishing emails
Emails purporting to have been sent by the University of Greifswald are constantly circulating. These emails contain links and a request for you to confirm your login details (i.e. username and password).
We would urge you not to respond to these emails.
As a general rule, please note the following: The University or the University IT Centre will never ask you to disclose or confirm your login details.
By the way
Phishing is not SPAM! Phishing emails are targeted attacks on users, not mass mailings sent worldwide. As a result, anti-spam mechanisms generally do not work in these cases. The URZ endeavours to set up individual filters as quickly as possible in response to reports of phishing.
