Educause Security Discussion mailing list archives

Re: .edu email phishing


From: Kees Leune <LEUNE () ADELPHI EDU>
Date: Tue, 1 Apr 2008 15:35:31 -0400

On 4/1/2008 at 2:47 PM, in message
<014801c89428$c73fa9a0$6502a8c0@PENTIUM43GHz>, Jimmy Kuo <cjkuo () verizon net>
wrote:

Was this a directed (against caltech.edu) attack or was this one of a family 

sent to other .edu lists?  Has anyone seen one like this for their school?

The return address was actually set up for:
 
We had our share late February/early March and also sent out a notice to our community. That seems to have worked, 
since as far as we can tell, nobody really fell for it. The reply-address was set to a Yahoo address. 

About a week ago, we got a second (much smaller) wave of the same phish, but it was phrased more urgently (final 
notice, account closure, etc.). The original phish originated from another .edu's network. We notified them, but never 
heard back. You are not the only one being targeted.

-kees


-- 

Dr. Kees Leune CISSP
Information Security Officer
Adelphi University
Garden City, NY 11530 
+1 (516) 877-3936

Current thread: