Unauthorised access to accounts
Unfortunately, a number of email programmes are now classified as spyware. These currently include
- Outlook
(currently still exempt: Outlook in Office LTSC (Campus licence)) - Edison Mail+
- E-Mail - Schnelle Mail
- bluemail
When setting up an email account in these programmes, the URZ login details are requested and subsequently transmitted to the providers. The entire mailbox is then copied to the provider, and all email - including outgoing mail - is handled via the providers.
This constitutes a breach of § 6(2) Sentence 3 URZ Regulations. To protect the university’s IT infrastructure, the URZ monitors email log data in relation to this matter and takes appropriate action.
What should you do if you are affected?
If you are notified by the URZ that you are affected by this security issue, please follow these steps:
- Check whether you are using one of the email programmes listed above. Remove your university email account from that email programme.
- If you are certain that you do not use any of the email programmes listed above, consider using an antivirus programme with a VPN function (e.g. Norton Anti-Virus). Disable the antivirus programme’s VPN function when checking your email.
- Change your password in the account management.
- Use an email programme recommended by the URZ.