Content (18)
The Cornell community has experienced an increase in phishing attempts over the past week. Scammers are impersonating the Office of Career Development and its employees to offer students work-study opportunities and remote internships. In some cases, these offers arrive on what appears to be…
Cybercriminals continue to target universities with email messages designed to steal credentials, financial information, and sensitive data. While Cornell's security systems help block many attacks, every member of the community plays an important role in identifying suspicious messages before they…
When critical systems fail at scale, the immediate impact is impossible to miss: grounded flights, stalled operations, and students suddenly unable to access assignments, submit coursework, or complete exams. But the outage isn’t the only problem.What follows—often within hours—is a quieter, more…
Using the built-in phishing report buttons in Outlook and Gmail helps improve future detection within those systems. But Microsoft’s reporting goes a step further— it doesn't stop with just moving the email to your spam/junk folder. Reports flow directly into Microsoft Defender, where security…
Cornell security liaisons, technical support providers, and those interested in learning more about security-related topics are invited to join the monthly IT Security SIG meeting.
Reporting tools built into Outlook and Gmail facilitate the designation of junk and phishing emails. Behind the scenes, these built‑in reporting tools are more than cosmetic updates; they play an important role in improving both individual inbox management and overall email security. Correctly…
Phishing and fraudulent email continue to pose a risk to the Cornell community. To help protect personal information and university resources, Cornell is streamlining how potentially harmful messages are reported.Cornell community members can choose either PhishAlarm or the built-in reporting tools…
PhishAlarm, a third-party solution for reporting suspicious email directly to the IT Security Office, proved successful over its two-year implementation. Since March 9, 2024, Cornell community members have reported 29,300 messages and 11, 276 of those were flagged as malicious by security team…
Previously, suspicious emails were reported either by forwarding them to the IT Security Office or by using a third‑party tool called PhishAlarm. Forwarding messages could result in unnecessary replies, and PhishAlarm will be retired in support of Resilient Cornell goals. This spring, Cornell…
Phishing and other kinds of fraudulent or deceptive outreach efforts are ramping up in terms of frequency and stealth at Cornell. So the IT Security Office is working to help the community learn to better identify and report suspicious email.Every quarter, through a simulated phishing attack,…
“Whaling” is a sophisticated form of phishing that targets an organization's top leaders. It uses clever social engineering and generative artificial intelligence to look like it’s from people you know and trust -- the president, provost, vice provosts, vice presidents, or deans.Cornell's leaders…
Watch out for fake job offers. Scammers are contacting Cornell students, pretending to be professors offering part-time research and administrative jobs. Students who apply end up losing their own money through fraudulent banking transactions.Be suspicious if a listing:
Phishing scams are more common now than ever before and have evolved well beyond the insincere pleas of imaginary displaced royalty hoping you’ll open a bank account for them. These days you may find that you receive a spoofed email, seemingly from your boss, asking you to purchase gift cards for…
Spoofing is when the "from" address is forged by the sender so the message appears to come from someone else. Practice extra caution:
Confirm the SourceVerify that the message is coming from the person's real email address. In email readers and devices that do not display the actual address, hover over the Sender’s name to reveal what follows the @ symbol. Scammers frequently attach a real person's name to a fraudulent email…
It is easy to fake what appears in the From or Reply-to line of an email message. Check the message headers to discover the message's real origin. Message headers are the material that comes before the body of a message.Quick CheckSometimes information in the headers contradicts the From line. For…
Beware of unexpected Duo (Two-Step Login) prompts. Ignore them unless you’re sure you requested them. If you are unexpectedly prompted to use Duo in a way you normally don’t, ignore it and contact the IT Security Office. For example, if you usually use your smartphone’s Duo app, but…
Scammers are following the headlines and taking advantage of fears surrounding the novel coronavirus (COVID-19). Stay informed and alert to avoid these and other targeted scams.