tidBiTS
Informs and engages the UNB community on IT developments and news

New Collection #1 Data Breach - is your information at risk?

tidBiTS

Posted: January 23, 2019 12:00:00 AM AST

Category: IT Security , Tips and Tricks , General Interest , IT Security Alerts , Design Desk


Earlier this month, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. This aggregate mass of credentials called ‘Collection #1’ has been prominent in the news lately. ITS...

Read the full post →


New Email Phishing Scam Targeting UNB

ITS

Posted: September 11, 2017 5:00:00 AM ADT

Category: IT Security Alerts , News , IT Announcements , IT Security , General Interest


A new phishing email has been discovered at UNB with the subject line “Final messages from University of New Brunswick admin”. The email claims you have important unread messages from the ‘University of New Brunswick Administrator’ and asks you to a click a link to review your messages and avoid service interruption. If you received this email, please do not respond or click on any links and report it to the UNB IT Service Desk right away at itservicedesk@unb.ca,...

Read the full post →


Are you a Bell customer You may be at risk

ITS

Posted: May 17, 2017 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


Bell, the Canadian telecom company, was recently the victim of a data breach in which hackers got access to the email addresses of approximately 1.9 million Bell customers. What does this mean to you? If you have an account with Bell, we highly recommend you reset your password immediately to help protect your account from malicious activity. Additionally, if you use the same password for your Bell account as your UNB or other accounts, please reset your UNB password and other account...

Read the full post →


WannaCry Security Threat - What this means for UNB

ITS

Posted: May 16, 2017 5:00:00 AM ADT

Category: News , General Interest , IT Security Alerts


Over the weekend, criminal hackers released a new strain of ransomware called WannaCry that has since infected an estimated 200,000 computers worldwide. This new security threat spreads itself automatically across all workstations in a network, preventing users from being able to access their data and files.  ITS is taking this risk very seriously and is working to ensure UNB’s exposure is minimized. How does WannaCry work? It begins with a phishing email - if you or a colleague...

Read the full post →


Phone Scam targeting UNB claiming to be from Konica Minolta

ITS

Posted: February 27, 2017 4:00:00 AM AST

Category: News , IT Security Alerts , General Interest


Some departments on campus are receiving phone calls claiming to be from Konica Minolta and requesting personal or UNB information such as departmental account numbers. If you receive a call of this nature, please do not provide any information; instead, hang up or ask for the name of the person calling and a call back number, then inform the ITS Help Desk at (506) 453-5199 or helpdesk@unb.ca and we will confirm the legitimacy of the call. If you have any questions, please contact the ITS...

Read the full post →


New Phishing Attack Targeting UNB

ITS

Posted: January 20, 2017 4:00:00 AM AST

Category: News , IT Announcements , IT Security , IT Security Alerts , General Interest


A new phishing email has been discovered at UNB with the subject line “HELP DESK URGENT UPDATE”, claiming your account has been locked due to a virus and asking you to login. If you received this email, please do not respond or click on any links and report it to the ITS Help Desk right away at helpdesk@unb.ca or (506) 453-5199. If you responded to this phishing email, please change your UNB password immediately and contact the Help Desk so we can check to see if there has been...

Read the full post →


Latest Phishing Scam Targeting UNB Disguised as Security Announcement

ITS

Posted: January 3, 2017 4:00:00 AM AST

Category: News , General Interest , IT Security Alerts


A new phishing email has been discovered UNB, claiming to come from ‘Campus Security Police’ and stating that a security issue has been identified on campus. The email encourages users to ‘read and follow protocol’ by clicking on a link. If you receive an email of this nature, please do not reply or click on any links - report it to the ITS Help Desk and delete it immediately. If you have any questions, please contact the ITS Help Desk at (506) 453-5199 or...

Read the full post →


Impact of lynda com security breach on UNB users

ITS

Posted: December 21, 2016 4:00:00 AM AST

Category: IT Security , General Interest , IT Security Alerts


Lynda.com was recently the victim of an unauthorized third party data breach. It is not expected that passwords or specific user accounts were accessed, however user course and contact information may have been accessed. Anyone who has logged in to a lynda.com account through UNB ITS within the past year has been notified of this issue. I have a lynda.com account - what do I need to do to minimize my risk? If you re-used a password you currently use for other online services, we suggest you...

Read the full post →


IT Security Alert Malware emails on the rise at UNB

ITS

Posted: December 1, 2016 4:00:00 AM AST

Category: IT Announcements , General Interest , IT Security Alerts


Over the past few days UNB’s IT security team has noticed a significant increase in emails with ransomware malware being sent to UNB in the form of Microsoft Excel and Word attachments. The UNB community is reminded to be careful when opening any files sent by email, including Office documents, and to continue to send suspicious emails to helpdesk@unb.ca if concerned or unsure of the validity of an email or its attachments. Several other Canadian universities have experienced sophisticated...

Read the full post →


New Email Phishing Scam Claiming to Come From University and College Presidents

ITS

Posted: November 9, 2016 4:00:00 AM AST

Category: IT Security Alerts , General Interest , IT Announcements


Several Canadian universities and colleges have recently been targeted with email phishing scams claiming to come from their institution’s president. The emails state you have received a ‘secure private message’ from the president and ask you to click a link to view the message. The link then takes you to a fake login page designed to look like your institution’s website in an attempt to trick you into entering your login information. If you receive an email claiming to come from UNB’s...

Read the full post →


The Latest Microsoft Phishing Email to Reach UNB

ITS

Posted: November 8, 2016 4:00:00 AM AST

Category: IT Security Alerts , General Interest


Recently reported at UNB, the latest phishing scam is coming via what appears to be a Microsoft email. The email informs recipients—supposedly on behalf of Microsoft—of updates to the ‘Microsoft Services Agreement’ and ‘Microsoft Privacy Statement’. It then gives instructions to click on a link to see the updates and says that failure to do so will result in having your email account suspended. If you’ve received an email that seems suspicious, do not respond or click any links; instead,...

Read the full post →


Recent Phishing Scam Targeting Telus Customers

ITS

Posted: November 3, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


Another phishing email was recently reported at UNB targeting Telus Mobility customers. The email informs recipients that ‘your monthly payment was recently declined’ and asks you to click a link to review and update your billing information to avoid problems with your account. Always think twice before clicking links in emails – if you receive an email that seems suspicious, contact the ITS Help Desk before clicking any links and they will help you determine if it’s safe. Protect Yourself....

Read the full post →


Download the latest update for your Apple iOS device today to prevent online spying

ITS

Posted: August 31, 2016 5:00:00 AM ADT

Category: IT Security Alerts


Do you own an iPhone, iPad or iPod? Due to a security flaw recently found in select Apple products, anyone with an Apple mobile device is strongly encouraged to download the latest software update from Apple, iOS 9.3.5, in order to reduce any risk to their personal information. What you need to know: - A company called the NSO Group has reportedly been taking advantage of security vulnerabilities found in popular Apple products.- Those who have been targeted are at risk of having their text...

Read the full post →


Keep an Eye Out for iTunes Security Phishing Scams

ITS

Posted: August 17, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


Cybercriminals have come up with another clever phishing idea targeting iTunes users. What to know: Cybercriminals are sending out emails (seemingly) on behalf of Apple The message informs you of a purchase supposedly made on behalf of your iTunes account and (1) asks you to confirm that this was authorized by you, or (2) asks for additional information/confirmation Since the chances of you having made the exact download for the exact amount they mention are rather slim, the scammers are...

Read the full post →


Phishing Attack on Illegal Game of Thrones Downloaders

ITS

Posted: August 3, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


For many, it may not come as a surprise that Game of Thrones is currently the #1 illegally downloaded T.V. show — which is likely why cybercriminals have chosen to target the latest phishing scam at people who have been illegally downloading the popular T.V. series. What does the phishing scam look like? Cybercriminals are sending emails that look like a notice from IP-Echelon (a company that enforces copyright claims) Cleverly, the email is made even more believable as it is forwarded...

Read the full post →


Cybercriminals are taking advantage of the new Pokémon Go craze

ITS

Posted: July 20, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


Having been recently launched, the new Pokémon Go app for Android and IOS has already reached peak levels of popularity and (of course) cybercriminals have found a way to manipulate everyone’s excitement. What you should be on the look-out for: Cybercriminals have made a malicious version of the app for Android and are likely to continue to do so in the future. Phishing emails have also been circulating. One of the reported scams involves sending an email to potential Pokémon Go players...

Read the full post →


Phishing Scam Targeting BMO Bankers

ITS

Posted: July 13, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


What you need to know about the BMO phishing scam: An email is supposedly being sent on behalf of the Bank of Montreal, asking for you to “please re-verify your BMO account” The email claims that, due to the current Canada Post strike, BMO has chosen to review their security protocols It informs that your debit card has supposedly “been locked for this reason” and provides a link for you to authenticate your BMO account information and restore your access What to do: DO NOT reply or click...

Read the full post →


The Latest Phishing Email Reported at UNB

ITS

Posted: July 13, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


What you need to know: The email is warning you that your WhatsApp subscription is expiring It advises that it is imperative for you to renew your subscription A link is provided “to perform a check of your information now, otherwise your account will be deleted” What to do if you have received the email: DO NOT reply or click on the link Inform the ITS Help Desk of the phishing attempt One of the most common scam emails comes in the form of a warning. This is meant to invoke enough...

Read the full post →


Heads Up TD Bankers Clever Cybercriminals Strike Again

ITS

Posted: July 6, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


Similar to the RBC phishing scam recently reported at UNB, we have now been made aware of the latest phishing email—this time targeting TD bankers. What you’re looking for: Cybercriminals are sending the email (supposedly) on behalf of TD Canada Trust They are offering a $245 credit to your TD EasyWeb account when you switch to online monthly statements by a certain date Links are provided for you to “make the switch” What you should do: DO NOT click on any of the links provided Report...

Read the full post →


Attention RBC Clients A Phishing Attempt Has Been Reported at UNB

ITS

Posted: June 29, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


Another convincing phishing email has been reported at UNB. What you need to know about the RBC phishing scam: An email is being sent (supposedly) on behalf of the Royal Bank of Canada It offers a credit of $375 to your RBC online account when you switch to online monthly statements by a certain date Links are provided to “make the switch today” What to do if you have received the scam email: DO NOT reply to the email or click on any of the links Report to the ITS Help Desk...

Read the full post →


Recent Netflix Phishing Scam

ITS

Posted: June 29, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


A clever phishing email has been reported at UNB. What to look for: This email is claiming to be sent on behalf of Netflix It notifies that your account has been put on hold because “we were unable to collect your last payment” It instructs to please update your payment method and provides a link for you to log in to your account and update your information as prompted What to do: DO NOT click on the link provided or respond to the email; simply report to the ITS Help Desk as with any...

Read the full post →


Beware Suspicious Construction Notice Reported at UNB

ITS

Posted: June 22, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


Beware of a suspected phishing email reported at UNB: The email is being sent as a notice of “changes in the house’s construction” It informs of plans to change the construction of your house’s surrounding grounds The sender advises to review the information about the prospective changes carefully and to “fill up a form and send it to the address” if you disagree with any of the plans Attachments are provided for your review If you have received a similar email: DO NOT open the...

Read the full post →


Don t get Hooked by the Latest Phishing Scam

ITS

Posted: June 22, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


What you need to know about the latest phishing email reported at UNB: It is being sent (supposedly) on behalf of the Canada Revenue Agency Claims to have sent you an INTERAC e-Transfer A link is provided with the description, “To deposit your money, click here” What to do if you have received a similar email: DO NOT click on the link (as tempting as it may be) DO NOT respond Report the email to the ITS Help Desk immediately It is important to stay updated on the latest scams and to...

Read the full post →


Warning Recent Orlando Tragedy Exploited

ITS

Posted: June 22, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


Cybercriminals have reportedly been using the tragic mass shooting in Orlando to their advantage. What you need to know about the scam: Cybercriminals are purposefully sending out phishing emails at a sensitive time, in an attempt to trick people into clicking on malicious links or opening dangerous attachments They are asking for your help with charitable donations to the victims and family’s involved in the tragedy They are providing links for you to click on to give financial donations...

Read the full post →


Malware attack at the University of Calgary

ITS

Posted: June 10, 2016 5:00:00 AM ADT

Category: IT Security Alerts


The University of Calgary is in the process of recovering from a significant, widespread malicious software (malware) attack. The attack resulted in 100 computers being infected along with widespread IT service disruptions that lasted nearly a week. The cybersecurity team at Information Technology Services at UNB has been closely monitoring the situation since the incident began and, along with universities across Canada, has offered its assistance. The aim of this advisory is to inform the...

Read the full post →


Be on the Look-Out for Extortion Email Schemes

ITS

Posted: June 8, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


The US Internet Crime Complaint Center (IC3) has issued an alert on extortion schemes that relate to recent high-profile data thefts. What it is: Cybercriminals will often use the news release of high-profile security breaches to their advantage; due to fear resulting from the recent reports, many people will fall victim to clicking on links or paying a ransom. Example: An email will be sent to inform you that information (such as your name, phone number, address, credit card information, or...

Read the full post →


LinkedIn Security Issue from 2012 Recently Resurfaced

ITS

Posted: June 8, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


LinkedIn’s 2012 security breach has recently come back to haunt us. Last month, LinkedIn officials became aware that the data stolen in the breach – including email addresses, hashed passwords, and member IDs – was being made available online. They have responded to the incident by invalidating all account passwords that have remained unchanged since the breach in 2012, and providing reassurance that significant steps have been taken to strengthen account security since then. LinkedIn...

Read the full post →


Microsoft Phishing Email Watch Out UNB

ITS

Posted: June 8, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


Recently reported at UNB, the latest phishing scam is coming via what appears to be a Microsoft email. The email is informing recipients—supposedly on behalf of Microsoft—of a new update that is important to “keep your email clean and safe”. The email gives instructions to click on a link in order to enable the necessary updates. It also warns that failure to complete the task will result in having your account suspended. *View a sample of the “Microsoft” phishing scam by logging in to IT...

Read the full post →


Phishing Email Reported at UNB Know How to Spot a Scam

ITS

Posted: June 1, 2016 5:00:00 AM ADT

Category: General Interest , IT Security Alerts


The latest phishing scam reported at UNB is coming in the form of a Last WARNING email. In this case, an email is being sent to supposedly warn people of their last chance to pay off outstanding debt. The email advises that the amount owed must be transferred in full by a certain date in order to avoid an additional fee, and to see more information by clicking on an enclosed payment notice. A Warning Email is just one example of emails commonly used for phishing scams. You can never be too...

Read the full post →


US-CERT releases alert on ransomware

ITS

Posted: April 28, 2016 5:00:00 AM ADT

Category: IT Security Alerts , IT Security


Ransomware has been making waves in 2016, with popular strains such as Locky being used to target UNB and similar institutions. How does your computer get infected with ransomware? Ransomware often piggybacks off of other forms of malware that show up on your computer. For example, a type of malware that steals banking information may infect the device first, followed quickly by ransomware to lock files and folders that may contain information, photos, and anything else deemed...

Read the full post →


Windows users advised to uninstall QuickTime as support from Apple comes to an end

ITS

Posted: April 22, 2016 5:00:00 AM ADT

Category: IT Security Alerts


Do you have the multimedia program QuickTime installed on your Windows computer? According to a recent report from Trend Micro, Apple is no longer supporting the Windows program, and as such, it should be uninstalled. Trend Micro also reported that QuickTime for Windows has two vulnerabilities that will remain unpatched. These vulnerabilities could allow cyber attackers to gain access to, and infect your computer unless QuickTime is uninstalled. To uninstall QuickTime from your Windows...

Read the full post →


It s CRA Tax Scam Season

ITS

Posted: April 13, 2016 5:00:00 AM ADT

Category: IT Security Alerts , General Interest


No, the Canadian Revenue Agency (CRA) isn’t actually trying to scam you. Cybercriminals, however, will try to steal your information by posting as the CRA during Tax season. With the ability to file your taxes online, many Canadians are expecting to receive an email from the CRA informing them of their assessment. Cybercriminals use this opportunity to send fake emails that notify the receiver of a tax refund they can claim. The amount of the fake refund can range from $500 to $1000, which...

Read the full post →


Surge of banking malware phishing attacks targeting UNB

ITS

Posted: March 22, 2016 5:00:00 AM ADT

Category: Our Community , IT Security Alerts , IT Announcements


A phishing email disguised as an invoice notice is targeting UNB and other institutions. The phishing email comes with an .rtf attachment that is infected with malicious software designed to steal banking information in order to commit online theft. If you have received an email of this nature, please report it to the ITS Help Desk and do not open any attachments. For more information on this phishing attack, visit TechHelpList’s spam list. Protect Yourself. Protect Your Stuff. Protect...

Read the full post →


Macs targeted by infected torrent websites

ITS

Posted: March 9, 2016 4:00:00 AM AST

Category: General Interest , IT Security Alerts


Over the past weekend (March 5 – 6), cybercriminals planted an infected torrent software on a website that specifically targeted Mac users. The software called Transmission, normally used to download files from Peer-to-Peer websites, was infected with ransomware that waited three days before locking the users’ files on Mac computers. This delayed strategy makes it harder to determine where the malware originates from. This recent attack left more than 6500 Mac computers at risk of being...

Read the full post →


Top 10 scams of 2015

ITS

Posted: March 3, 2016 4:00:00 AM AST

Category: Tips and Tricks , IT Security Alerts


In 2015, we reported on some of the most severe online threats, such as Stagefright, Angler, and even UNB-specific phishing emails. In recognition of Canada’s 12th annual Fraud Prevention Month, it’s time to brush up on your awareness skills for more than just online threats. Check out the Top 10 Scams of 2015, and what to watch for in 2016 to see where else you may encounter a scam. Protect Yourself. Protect Your Stuff. Protect UNB. Visit go.unb.ca/itsecurity to learn more. For...

Read the full post →


Infected Word documents They re here and they re a serious threat

ITS

Posted: February 24, 2016 4:00:00 AM AST

Category: General Interest , IT Announcements , IT Security Alerts


Many experts have seen it as the inevitable when it comes to cyberattacks, but it is finally here. Ransomware-infected Word doc attachments are reaching users’ email inboxes and they’re difficult to recognize as being infected. The new malicious attack, dubbed “Locky”, tricks people twice to have their information held for ransom. First, they trick you into opening the word document. Secondly, they try to trick you into enabling Macros on the Word file. If you don’t already have Macros...

Read the full post →


Employee Payroll Scam hitting universities across North America

ITS

Posted: January 27, 2016 4:00:00 AM AST

Category: General Interest , Our Community , IT Security Alerts


An Employee Payroll email scam is once again hitting universities in Canada and the US, informing faculty and staff members of a change in their human resources status. An alert issued by the FBI in January of last year outlines what signs to look for to detect the scam email, as well as the consequences of falling for scams of this nature. Check it out. Have you received an email that is similar to this alert? Report it to the ITS Help Desk and delete it immediately. Protect Yourself....

Read the full post →


Netflix phishing email on the loose

ITS

Posted: December 9, 2015 4:00:00 AM AST

Category: IT Security Alerts


Have you received an email from Netflix informing you that your account details need to be updated? Scammers are once again after login credentials for Netflix via a fake email claiming to be from the popular streaming service. What can they do with your Netflix Credentials? Besides being able to enjoy some quality streaming on your dime, more importantly they can steal your credit card information and other personal information stored in your Netflix account. Avoid this and other email...

Read the full post →


RCMP Phone scam is a wakeup call you don t want to fall for

ITS

Posted: December 9, 2015 4:00:00 AM AST

Category: General Interest , IT Security Alerts


Scammers are calling people early in the day, or late at night, pretending to be the RCM and trying to trick you into forking over money to pay a fine or taxes. To push a sense of urgency, the scammers will even threaten to arrest you within 24 hours if the fine or taxes are not paid. Although this scam has been floating around since 2014, there are still variations being used today. To learn more about this telephone scam, including what to do if you’ve received a threatening call like...

Read the full post →


Exploit kit Angler used to hide malware onto webpages

ITS

Posted: December 2, 2015 4:00:00 AM AST

Category: General Interest , IT Security Alerts


An exploit kit used by cybercriminals is making waves again, infecting countless webpages and unsuspecting users who visit those pages. An exploit kit such as Angler is a toolkit used by cybercriminals by being injected into hacked websites. When the infected website is visited, the exploit kit will examine extensions, plugins, and add-ons used by that user and look for vulnerabilities to slip through the cracks. One of the key signs of an infected webpage is if a misleading dialogue box...

Read the full post →


New phishing scam making waves at UNB pretending to be a faculty member

ITS

Posted: November 26, 2015 4:00:00 AM AST

Category: Our Community , IT Security Alerts , General Interest


A suspicious email has been spotted by UNB students, faculty and staff, pretending to be from a faculty or staff member on vacation who is stranded and in need of money urgently. In some cases, these emails come from fake email addresses disguised to look like legitimate emails from the faculty or staff member, while other times they are sent from actual UNB email accounts that have been hacked. Do not fall for this phishing email; do not respond or click any links, and delete the email...

Read the full post →


New Remote Access Tool being used maliciously on Android Windows and OS X

ITS

Posted: November 26, 2015 4:00:00 AM AST

Category: IT Security Alerts , General Interest


Cybercriminals are turning to a new remote access tool and using creative text messages to slip it onto unsuspecting users’ devices. Though the new software, called OmniRAT, can be used for legitimate purposes, it is also being used to spy on users and even hijack their Android, Windows, and Mac OS X devices. Users are receiving a text message telling them a multimedia message cannot be delivered directly to them because of the StageFright Vulnerability. Included in the text message is a...

Read the full post →


Cybercriminals are phishing for your Apple ID

ITS

Posted: November 10, 2015 4:00:00 AM AST

Category: General Interest , IT Security Alerts


Have you received a suspicious email lately that looks like it came from Apple? Don’t be fooled by the “legitimate” Apple logos. A new phishing email is targeting Apple customers worldwide, with a message that notifies them of limitations that have been put onto their account as part of Apple’s security process. The message also ensures the recipient that “our aim is purely to protect you and your account” followed by a sense of urgency to provide information and resolve the issue as...

Read the full post →


Fake Email being sent to UNB students faculty and staff claiming to come from the Microsoft Outlook Team

ITS

Posted: November 2, 2015 4:00:00 AM AST

Category: IT Security Alerts , General Interest , IT Announcements


Recently there was a phishing email sent to UNB students, faculty, and staff notifying them of a change in their calendar, pretending to be sent from the Microsoft Outlook Team. If you have received an email like this with a request to click a link within the email, please do not respond or click any links and delete the email immediately. This is a phishing attempt to steal your information, such as your UNB credentials. If you responded to a phishing attempt and gave out your UNB username...

Read the full post →


New telephone scam targeting UNB is one wakeup call you don t want to fall for

ITS

Posted: October 29, 2015 5:00:00 AM ADT

Category: IT Security Alerts , IT Announcements , Our Community


Have you received a call from “Nancy” or anyone else claiming to be from Global Technical Department? This latest telephone scam targeting UNB members, claims to be from a department located in the Law Library and requests to go through steps to protect your computer system. What they’re really requesting is to gain access to your computer and steal your personal and UNB information via remote access tools, allowing them to take control of your computer from afar. They pretend to show you...

Read the full post →