Educause Security Discussion mailing list archives

Releasing details


From: Theresa Rowe <rowe () OAKLAND EDU>
Date: Tue, 22 Jan 2008 16:31:36 -0500

We sometimes get requests from student and staff that read something like
the following:

"Joan Doe called the Help Desk asking for if we could trace an IP address of
a
computer that sent an email from her account on January 19 sometime around
3:30 AM.
She said that someone had hacked into her email account and deleted some
messages as well as sent some. She has since then changed her password but
is now
looking to take action on the person that sent it."

Do you have protocols on how you handle such an incident?  In most of these
cases, the logins look authentic - i.e., the real ID and password were used.


--
Theresa Rowe
Chief Information Officer
rowe () oakland edu
Oakland University

Current thread: