Educause Security Discussion mailing list archives

Re: Response to phishing e-mails


From: Colleen Blaho <cblaho () SAS UPENN EDU>
Date: Mon, 27 Oct 2014 14:30:13 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The university I'm enrolled in puts out a notice within a few hours
after the incident along the lines of "There's this phishing email
going around, don't click it". The users that report it go "Oooh! my
report did something good!" and the users that didn't report it know
not to click the email. Either way, you reinforce that phishing is bad
and reporting is good.

On 10/27/2014 02:23 PM, Leland Lyerla wrote:
As they become more aware of how to identify phishing e-mails, our 
faculty and staff let us know via e-mail when they come across one
in their in-box. I do not want to discourage their vigilance, but I
would appreciate any suggestions on how to manage/respond to these
messages.



Leland


- -- 
Colleen Blaho

Information Security and Unix Services
University of Pennsylvania
School of Arts and Sciences
3600 Market St.
Suite 501
Philadelphia, PA 19104
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUTo8vAAoJEGuluYz5V31rulMQAMl1oT81bupQZyS3NRmy5wqV
YM5m36MlNvoozvJ766WBFnpAUpA0MRpsmYubDo8OTukTsfYR8rEohFXUNU338+Y+
uON5U7H/lfYctVefYTV3ajmJVnlU+W0ck/fqXxRHWjLGe9g834VjoBW5Do2p71GS
M9J4xi/MH+Xg9FMgXqwTwPw0L/1+MzXJKLJ+SX+7nHnYsPrNUNjHRkqeXvjoBeRY
Zl+bLiyMB36nSociJz2kG5Y/lr2bGVjh7lsIU1eIakv9NDeVOp2GDAQP6ZWBoO22
+npW5RqGlU3JnjP72Vx84jKolfKr2FxfGe32CcQDojuTKMU9X2Mn4hukk4QJwV+7
0BIVOmWCd/c1vwbcHKTaZv57JAMyd9oVcjiw6A3DP9yOSv7xrXQx61RVXqSoh4fl
Aa2cZIbLIbq7xnOjswbyAAee3PEuznNJEPiykISPa9juWjc0GK46XQl0BrCv2GLb
3j0R0qELAr56q+gicv/fTOJZakdrDcVM1qKO3NnosMfX+F1B6VAHnIIoKXAWaBns
b8+BxvG7SFVo8Fcz3NRMtDhJXnORaMdSgFwt48NUefkh05IolJIbF2Sh0nGmAZHJ
utLWyp2OMTcpsUoe3sD4tj7pxmWDUspzuItTSHDy3YIpC4R/4fZoujX7gNYshXjM
CVTAjNee0BHUdglnm3sy
=qBuE
-----END PGP SIGNATURE-----


Current thread: