Educause Security Discussion mailing list archives

Re: Unusual pattern of compromised accounts


From: Chris Grooby <cgrooby () GMAIL COM>
Date: Fri, 26 Jan 2018 17:02:40 -0500

Hello
Yes, we had three accounts siphoned with paycheck redirects to GreenDot and
we contacted FBI to report them.  This happened last November.

Christine Grooby, CISSP, CISM
Div Manager InfoSec
Water Utility, Maryland


On Fri, Jan 26, 2018 at 4:17 PM, Pollock, Joseph <PollockJ () evergreen edu>
wrote:

Has anyone observed the following:



1.        A cluster of compromised accounts with no indication of a
common factor such as clicking on a phishing link. Users have no idea how
the compromise occurred.

2.       The culprits change the user’s direct deposit authorization

3.       They may have been familiar with the Banner system.

4.       No other activity was observed.



We are looking for other indications,  such as compromised desktops,  but
have found nothing as yet.



Please reply outside the list if you wish.



Joe Pollock

Network Services

The Evergreen State College


Current thread: