About Us | ListProcs | One-Stop Service | Services | FAQs | University Computing & Telecommunications | home

 


Dealing with Phishing Attempts

SJSU is a regular target of "phishing" schemes; e-mailed attempts to trick employees and students into revealing usernames and passwords to unknown third parties. These e-mail messages may be simple and primitive, or they may be skilled forgeries based on real e-mail notifications.

  1. How do you recognize a "phishing" scheme?
    Phishing schemes ask for confidential personal data, like your password, in e-mail.
  2. Phishing schemes often threaten immediate penalties for not following their instructions.
  3. Phishing schemes often ask you to reply to an address that isn't associated with SJSU or the agency the message claims to be from.
  4. Phishing schemes often supply a web link that appears to be an SJSU link, but connects to a different website when it opens in your browser.

What doesn't SJSU (and other legitimate agencies) do via e-mail and the web?

  1. SJSU does not send automated messages asking for your username and password. Internet mail distribution is not secure enough to be trusted for this purpose.
  2. SJSU does not request passwords using unsecured web pages or non-University web pages. All web password requests should be at an address that starts with "https://" (note the letter "s") and that includes "sjsu.edu/" in the server name. Please check the "Address" line in your browser for mismatches or fraudulent typos when you open a web page.
  3. SJSU does not send automated system warning messages that require immediate response to avoid immediate penalties. SJSU automated system warnings ideally provide a reasonable time in which to respond, and will tell you how many days or weeks in which you have to respond.
  4. SJSU does not implement automatic notification tools without informing the helpdesks and desktop support technicians.

Some resources to use in education about phishing attempts:

Reporting phishing Scams:

FTC: National Resource for Identity Theft

You can also report the phishing scam to the Anti-Phishing Working Group and to the FTC at spam@uce.gov .

YouTube Videos on Phishing

Video: Videos of the Week (Vol. 10): Phishing Trips (Harvard)  

Video: Identity Theft Prevention | How to Prevent Phishing Scams  

iSafe Video on phishing:

http://ftc.isafe.org/imgs/phishing.swf

 

 

UCAT - University Computing
San José, CA 95192-0209
408.924.2340
Located in: CC 2nd Floor
contact us | campus map

Don Baker,
Interim Associate Vice President