[104724] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Fake-alert: VERIFY YOUR MERIT.EDU WEBMAIL ACCOUNT

daemon@ATHENA.MIT.EDU (Graeme Fowler)
Sat May 24 12:16:00 2008

From: Graeme Fowler <graeme@graemef.net>
To: peter@peter-dambier.de
In-Reply-To: <48382E10.70904@peter-dambier.de>
Date: Sat, 24 May 2008 17:14:33 +0100
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org

On Sat, 2008-05-24 at 17:02 +0200, Peter Dambier wrote:
> I dont trust it:

Quite right too, it's a spear-phishing attack. This is currently an
almost daily occurrence for .edu domains.

The compromised accounts are frequently abused via webmail systems,
being used to send out more scams.

The scammers responsible are also targeting UK higher ed institutions,
with a limited degree of success. I can't really speak for my US
counterparts with regards the success of the attacks, but one would
surmise that it's more or less the same. To paraphrase badly:

All users are gullible, but some are more gullible than others.

-g



home help back first fref pref prev next nref lref last post