Fraudulent messages - phishing

Last modified by Denisa Wernerová on 03.08.2023 12:55

Do not try to fight phishing on their own, because in many cases it can disrupt the already established and proven practices of our security team at the Technical University.

If you read the message with many hours delay (more than about 12 hours), usually already we know about this incident and there is no need for us to report news! Please forward fraudulent messages to abuse@vsb.cz immediately after delivery to your inbox. Thank you for your understanding.

Report to us only fraudulent messages. Security team at the Technical University do not solve common spam messages, such as supply of Viagra pills, advertising messages and messages with infected attachment.

Content:


What is phishing
These are a fraudulent e-mail messages or web sites from which attackers want to lure users of confidential information such as login accounts, PIN to cards, etc.


How to recognize a phishing

  • With graphic design of the message attackers are trying to give the impression that the message was send by an organization whose clients are attacked. 
  • Text can look like information about non-payment, call for verification of the password validity or its change or as client satisfaction research with a service.
  • In the message text is a link which should look that it is directed to the websites of the organization (bank) but on closer examination you find out that it is linked to somewhere else and there are fraudulent websites.
  • In the browser address line is showed different address than address of the organization whose clients are attacked. Sender address can also be from different domain than websites of the organization (you see it after showing head of an email).
  • Message/form encourages you to share information that would not be required by the organizaton.

[source: http://www.hoax.cz/phishing/]


Read carefully and use common sense

  • You win one million pounds!
    Did I bet?
  • Pay the bill!
    Did I ordered something?
  • Your inbox is full!
    I greased e-mails last week. Could I really fill inbox so quickly?
  • Send us an additional personal information, otherwise we will ... !!!
    I have no agreement with the organization and I did not want anything.
  • Tell us your password, your administrator!
    At CIT they are far more privileges than I am (an ordinary user).
  • So this is not!
    • Do not write your password on the bottom of the screen and for sure do not tell it anyone.
    • When someone imitate my signature, I will give it a criminal complaint, but the electronic signature that is just such a crazy farce IT guy. Something like a computer game.


How you can help


What can you do to protect your account security

  • please, report us suspicious messages immediately on abuse@vsb.cz and leave the message in the mail until you are asked (for case that you won't sent all necessar information),
  • never reply to suspicious messages,
  • don't click on links in suspicious messages,
  • tell nobody and never your login and password.


I responded to a suspicious message

  • change disclosed password immediately (see password change),
  • don't be affraid and don't be shame we are happy and willing to help you. Please report us the situation and we also investigate if someone else has been also caught.


Samples of fraudulent messages

  • View message head detail in the email client and check addresses. From and Reply-to. Don´t tell your login and password by email.

Example No. 1

phishing.gif
 

Example No. 2

phishing_2.gif

Example No. 3

phishing_3.png
Example No. 4

phishing_4.png

Example No. 5

phishing_5.png

Example No. 6

phishing_6.png

Example No. 7

phishing_7.png

Example No. 8

phishing_8.png

Example No. 9

phishing_9.png