<?xml version="1.0"?>
<News hasArchived="false" page="2" pageCount="2" pageSize="10" timestamp="Fri, 28 Aug 2026 10:42:30 -0400" url="https://my3.my.umbc.edu/groups/doit/posts.xml?page=2&amp;tag=phishing">
<NewsItem contentIssues="false" id="147565" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/147565">
<Title>Beware of PayPal "New Address" Emails</Title>
<Tagline>New approach (to phishing). Same goal.</Tagline>
<Body>
<![CDATA[
    <div class="html-content">
    <div>
    <p>Cyberattackers constantly evolve their tactics to bypass organizational defenses.  A recent trend involves exploiting PayPal's gift address feature to deliver phishing messages.  These messages may include a fake support number to trick recipients into calling or malicious links designed to steal account credentials.  In either case, the attacker's goal is to compromise your PayPal account.</p>
    <p>If you receive a PayPal notification about account changes or a sent invoice, <strong>do not</strong> click any links in the email. Instead, directly type the official PayPal URL into your web browser to ensure you're interacting with the legitimate PayPal website, not a fraudulent copy.</p>
    </div>To learn more about this new method of attack: <a href="https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/" rel="nofollow external" class="bo">https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/</a>
    </div>
]]>
</Body>
<Summary>Cyberattackers constantly evolve their tactics to bypass organizational defenses.  A recent trend involves exploiting PayPal's gift address feature to deliver phishing messages.  These messages...</Summary>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/147565/guest@my.umbc.edu/2b59018686410f6eb3b93de02b62bc12/api/pixel</TrackingUrl>
<Tag>phishing</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="original">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/original.png?1761588639</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="large">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/large.png?1761588639</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/medium.png?1761588639</AvatarUrl>
<AvatarUrl size="small">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/small.png?1761588639</AvatarUrl>
<AvatarUrl size="xsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxsmall.png?1761588639</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>2</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Mon, 24 Feb 2025 09:09:35 -0500</PostedAt>
</NewsItem>

<NewsItem contentIssues="true" id="147530" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/147530">
<Title>Financial Aid and Job Offers Email</Title>
<Tagline>It seemed phishy because it was!</Tagline>
<Body>
<![CDATA[
    <div class="html-content">
    <div>This morning, several individuals received a phishing email disguised as a job opportunity. We want to thank everyone who reported it. Your reports allow us to take immediate action to protect others.</div>
    <div><br></div>
    <div>If you receive a suspicious email, please report it. Google provides the ability to report phishing in your web browser by clicking the three vertical dots next to the email sent date and selecting "Report Phishing." You can also forward the email to <a href="mailto:security@umbc.edu">security@umbc.edu</a>. Both options create a ticket for our team.</div>
    <div><br></div>
    <div>Phishing is the use of deception to obtain sensitive information. In this case, the email attempted to collect your personal information. There were a couple of red flags that make it clear it is phishing:</div>
    <div><ol>
    <li>The email claimed to be from the Career Center but was sent from a personal Gmail address (not @umbc.edu).</li>
    <li>The link to the UMBC application portal redirected you to a Google Form, not UMBC's official portals.</li>
    <li>The Google Form was asking for personal information.</li>
    <li>The email requested that replies be sent to a personal Gmail address instead of the Career Center's UMBC email address.</li>
    </ol></div>
    <div><img src="https://my3.my.umbc.edu/system/shared/attachments/news/000/147/530/47b6ed0b6b6824c8dc892e2e48b462f9/Phishy%20Email.png" style="max-width: 100%; height: auto;"></div>
    <div><br></div>
    <div>Thank you again to all who reported the phish!</div>
    </div>
]]>
</Body>
<Summary>This morning, several individuals received a phishing email disguised as a job opportunity. We want to thank everyone who reported it. Your reports allow us to take immediate action to protect...</Summary>
<AttachmentKind>Image</AttachmentKind>
<AttachmentUrl>https://assets4-my.umbc.edu/system/shared/attachments/37c0b02c8023d5961f9ee9b8d83f998d/6a919e56/news/000/147/530/47b6ed0b6b6824c8dc892e2e48b462f9/Phishy Email.png?1740148103</AttachmentUrl>
<Attachments>
<Attachment kind="Image" url="https://my3.my.umbc.edu/groups/doit/posts/147530/attachments/55666"></Attachment>
</Attachments>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/147530/guest@my.umbc.edu/0b9728621d8f27afc862cd897158196f/api/pixel</TrackingUrl>
<Tag>phishing</Tag>
<Group token="itsecurity">IT Security - DoIT Cybersecurity Assurance and Digital Trust</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/itsecurity</GroupUrl>
<AvatarUrl>https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="original">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/original.png?1761588639</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xlarge.png?1761588639</AvatarUrl>
<AvatarUrl size="large">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/large.png?1761588639</AvatarUrl>
<AvatarUrl size="medium">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/medium.png?1761588639</AvatarUrl>
<AvatarUrl size="small">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/small.png?1761588639</AvatarUrl>
<AvatarUrl size="xsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xsmall.png?1761588639</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/001/660/859c6838736bc30c98279ed45d7fd70a/xxsmall.png?1761588639</AvatarUrl>
<Sponsor>IT Security - DoIT</Sponsor>
<PawCount>7</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>false</CommentsAllowed>
<PostedAt>Fri, 21 Feb 2025 09:37:54 -0500</PostedAt>
<EditAt>Fri, 21 Feb 2025 09:38:22 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="144550" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/144550">
<Title>Cybersecurity Awareness Month: Avoid Phishing Attacks</Title>
<Tagline>Protect data by recognizing &amp; reporting phishing attempts</Tagline>
<Body>
<![CDATA[
    <div class="html-content"><span><h3><strong>Phishing</strong></h3>
    <p><span>Phishing is the use of deception to acquire passwords, credit card numbers, or other sensitive information from a user. There are many phishing mediums including SMS messages (Smishing), voice calls (Vishing), and email which is the most common phishing medium. Within emails, users should be wary of malicious URLs or attachments.</span></p>
    <p><span> </span></p>
    <p><span>Phishers typically pose as a trusted entity, such as a system administrator or service provider, in order to scam their victims. Often, these messages will ask for the user to communicate in some other means; for example, a message may request that a victim send an SMS message to a specific number or reply using a personal email address. These messages will also imply some sense of urgency for the request, thus leading an unsuspecting victim to react quickly without first asking themselves whether or not the message is legitimate.</span></p>
    <p><span><br></span></p>
    <h3><span><strong>Recent examples of phishing scams at UMBC: </strong></span></h3>
    <p><span><br></span></p>
    <ul>
    <li><p><span>Fake job offers </span></p></li>
    <li><p><span>Google forms requesting usernames and passwords</span></p></li>
    <li><p><span>Gift card scam </span></p></li>
    </ul>
    <br><p><span><span><span><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcTU_N3WMdmA9ZFefqHM3oEJtzf_I5ZkDd2Zf3cDzCBcWNfNh-S-fa1lDr_nIDIu_yubJ9xc6DStsh3kQEdbeMiXddELjYOWhKLwhMSOBNkHwjdIdRGkNdER9zbXrps3_-CfkHnmfmKzEotrkAjYy2-1kZP?key=ciB3wloKbf3CHOE_YTEWCg" width="367" height="471" style="max-width: 100%; height: auto;"></span></span></span></p>
    <br><p><br></p>
    <h3><span>To spot phishing emails, look out for the following:</span></h3>
    <br><h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdHjcUYLpcl8lhI85q3j6MNBKrVPZ3UHNz_Yfpzr_luglvz8ZQqvzlujFU3FN5wVW3I2_uTaKUjmjrYg2BJuUNGxHcC9VNoF6F72P7nBHVfVLoy3vUNc-jW0QkPPIrwkLNm1LsUQw0AM0WtUFKm4BsHIQ91?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> Unexpected messages making unexpected requests</span>
    </h3>
    <p><span>Does this email or direct message come from an unfamiliar sender who claims to know you, or a friend who you have not spoken to in a long time? Does the list of recipients contain people you don’t know or talk to? This is particularly true if the message asks for money or personal information.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfYrijO2qCQx8eKCHNsUmTdWuzqjJZ3_n8aC2bFQxIDwuvZIHZAHbxVmZmWvsoN08NctrE8GHpulFgYg3MJWyISRJuAoQujSIqOkntR_C5Y1OHnbf3keJ45MqUkn19XhPi3q-894Ap6ke8JvwzRCtXeWHbX?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> An urgent tone</span>
    </h3>
    <p><span>If the sender says you must act now and uses fancy jargon or other intimidating language, ask yourself why.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcxcTEF-UEnPuABhp0NQvYhZNtK8UDIHqrDMalnxMqs_Fkslq15t_kiy0kaKEiGhjKZ59_Jg-5UwzWzqq9xWKMQzibc-PR1-BotwobO5VWH6-sqxKrmE0s3E0kfJk3BOxeZw8ye0BoRC408S-SCxhAfrkk?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> An offer that’s “too good to be true”</span>
    </h3>
    <p><span>It probably is, especially if important information like an employer’s address or a product’s shipping information is nowhere to be found.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcsyPY2bvGiM-aRgJZllk56Vn2j4eS2fA1n4Ik6NCKXq6hriIC0sQNkJhbakDi2K386SsWum6sF7JNnYvzQSqWoP9Xj6rMisrpyUjWP4q7WH7eZUMg9Ew9-zyh7Z1-wXSZc8WrJato4wyXWK9eJ1C7hceCz?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> Phishy Links and Email Addresses</span>
    </h3>
    <p><span>Hyperlinks and sender emails appear to correspond to known domains and people, but something, sometimes a single letter, has been changed. This may require close examination; look for misspellings, dashes, or other deviations from what seems to be a legitimate domain.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcSwEBDHvjynP6ZzARzItAyo0_XljQwFSQeS-_76uoiZifRbDuIypoQf6bl3JffyIwuI1sLIhIy7pW1hOSVImGDSaf3sWHt4vJAGzP7Bm5V0WWku0a9jiEwbfVhfRLyDpnqP-BKnk2lE5HNT3SPJf2Mc9z9?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> Valid name, but strange domain in email address</span>
    </h3>
    <p><span>For example, UMBCPayroll@gmail .com, umbcpresident@yahoo .com, or financialaid413@hotmail .com</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXeua5MahO353AEM9rL84hYjV3TDK3nUTlNGiiEUFqk3XrWOXtqeg7OTH87xCPpayqAk1kKDSMGRZYzBtdEr1BmgkRIgY7-S4RXf3-kcv2tpWbcTTI_HSs1IC4ebJIckPTTPWSHInn5U9ehdIAx9yo0WNdgG?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> An email requests your password, your credit card number, or other sensitive information</span>
    </h3>
    <p><span>Email is never secure for sharing this type of information, and most trusted services should already have it. On sites that ask you to provide personal information like your credit card, look for “https” in the address bar to ensure the site is secure. UMBC will never request your password in an email.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcHZDC-x2GInClMUIGBkzPNbv9w4f3BPuP1dfTxec--bgTvQIZSaHaLGjabvWQNwlRcewaaqImZYIUaQ_poTyaIVwGcKrA2Z3MFQrsJqZh70kO3XevPMGyNnnlC26fA0VCwA1_Vnwvj3SOctUDi5Xy3OmQ?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> Request for a cell phone number</span>
    </h3>
    <p><span>In many recent phishing messages, the hacker requests that you send them your cell phone number so that they can ask you a question.  Why would a legitimate person needing assistance not just ask you the question in the email message, rather than asking for your phone number?</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfmnRrlxUbTmfAhlrODeRcLKbhGaYR-PfcG72M5P-fEtsZDUUCIN2bPFBYBNJDI1JD5mH1CuQmsUihJ4iVOLE8uIT4DcYwLpvhOwV2zVFbFqfhG98iwctbo2YjDkCtBH6dAI_1o09MvMsU6x_CD8M-1oaCW?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> A prompt to open an attachment or follow a link</span>
    </h3>
    <p><span>Critically examine any email with an attachment, especially an unexpected one. If the link prompts you to “Sign In” to an account, be extra suspicious. Do not “Enable Macros” or allow similar permissions for attachments you do not trust.</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcdIEmlYbVXOGEaTdk2SlJZVT3Umbo2R0QEHZTy6qTxcDikL9q5_yltPeqAeMIq0iRRvgQ0jiwmBanzDJDOHAccvC5xwbsJbz_gNtJNcOYB-2axo0Rng6_U30Jz9EnSffPMepSaOYZ4-21kbxoMYeMB-M4B?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> The time zone/send time of the message is unusual</span>
    </h3>
    <p><span>For example, why would a member of the University community be sending a message with a time zone that is appropriate for Eastern Europe?  Is it suspicious for a UMBC community member to send an email message at 3 am?</span></p>
    <p><br></p>
    <h3>
    <span><span><img alt="Cross Mark" src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXcgRVHboCSgNrKv3XvpZtptbeTq9nc4N6MiA9qZhdsa_lBD_ADcC7sKp-DrC9llI-L3spO7KzD2NvbYSlCYYBl9E6LKO5AkZcUyM7vJKnzAC_Pm0F-m0kMj0Lw9clfs5s2SchFp-gr92a71vTfXUSan3c8K?key=ciB3wloKbf3CHOE_YTEWCg" width="20" height="20" style="max-width: 100%; height: auto;"></span></span><span> Something “off”</span>
    </h3>
    <p><span>Phishing emails often have an impersonal, awkward, unprofessional, or out-of-character tone. Many - but not all - phishing emails contain conspicuous typos, bizarre capitalization, strange grammar, or numbers used in place of letters.</span></p>
    <p><br></p>
    <h3><span>Report</span></h3>
    <p><span>If you have any questions about whether or not the mail you've gotten is legitimate, please contact the DoIT Security Department at <a href="mailto:security@umbc.edu">security@umbc.edu</a>. </span></p>
    <div><span><br></span></div></span></div>
]]>
</Body>
<Summary>Phishing  Phishing is the use of deception to acquire passwords, credit card numbers, or other sensitive information from a user. There are many phishing mediums including SMS messages (Smishing),...</Summary>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/144550/guest@my.umbc.edu/4c28b8c092600f7cac236b0c62f0c4a2/api/pixel</TrackingUrl>
<Tag>attacks</Tag>
<Tag>bsg</Tag>
<Tag>phishing</Tag>
<Tag>scam</Tag>
<Group token="doit">Division of Information Technology (DoIT)</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/doit</GroupUrl>
<AvatarUrl>https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="original">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/original.JPG?1727453227</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="large">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/large.png?1727453227</AvatarUrl>
<AvatarUrl size="medium">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/medium.png?1727453227</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/small.png?1727453227</AvatarUrl>
<AvatarUrl size="xsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxsmall.png?1727453227</AvatarUrl>
<Sponsor>Division of Information Technology (DoIT)</Sponsor>
<ThumbnailUrl size="xxlarge">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/xxlarge.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/xlarge.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="large">https://assets2-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/large.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="medium">https://assets2-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/medium.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="small">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/small.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="xsmall">https://assets4-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/xsmall.jpg?1728320288</ThumbnailUrl>
<ThumbnailUrl size="xxsmall">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/144/550/c41ad03d24c4c2b85236ddbccf893c91/xxsmall.jpg?1728320288</ThumbnailUrl>
<PawCount>5</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Mon, 07 Oct 2024 14:11:42 -0400</PostedAt>
<EditAt>Tue, 08 Oct 2024 14:24:37 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="false" id="129968" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/129968">
<Title>Protecting your online accounts over winter break</Title>
<Body>
<![CDATA[
    <div class="html-content"><span><p><span>As we prepare for the winter break, we commonly see a surge in malicious activity toward user accounts. Users receive emails warning about unpaid invoices, expired passwords, or full inboxes. These messages are made to convince people that they are in danger of losing money or access if they don't respond, or click a link within an email. Very often these messages will appear to come from someone you know, from a company you may have done business with, or in some cases, from what looks like your own account.</span></p>
    <p><span>Other common phishing messages recently have included invoices from companies like PayPal or GeekSquad saying they will be charging your credit card if you don't click a link. These messages are fake. </span></p>
    <p><span>We have some FAQs available on how to identify phishing/spam messages you can look at below.</span></p>
    <p><a href="https://itsecurity.umbc.edu/cyber-awareness/spam-and-phishing-faqs/" rel="nofollow external" class="bo">UMBC Phishing and Spam FAQs</a></p>
    <p><span>As well as some best practices for keeping your account secure:</span></p>
    <p><a href="https://itsecurity.umbc.edu/cyber-awareness/" rel="nofollow external" class="bo">Cybersecurity Awareness - Security - UMBC</a></p>
    <p><span>If you receive any messages like this, please forward them to <a href="mailto:security@umbc.edu">security@umbc.edu</a> along with the email headers. For instructions on forwarding email headers, please visit:</span></p>
    <p><a href="https://wiki.umbc.edu/pages/viewpage.action?pageId=1867970" rel="nofollow external" class="bo">How do I forward full email headers? - Find Help (FAQs) - UMBC.</a></p>
    <div><br></div>
    <div>--</div>
    <div>Damian Doyle</div>
    <div>Deputy CIO and Interim CISO</div>
    <div>Division of Information Technology</div>
    <div><span><br></span></div></span></div>
]]>
</Body>
<Summary>As we prepare for the winter break, we commonly see a surge in malicious activity toward user accounts. Users receive emails warning about unpaid invoices, expired passwords, or full inboxes....</Summary>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/129968/guest@my.umbc.edu/4b0b31dc07b45e6e7ffe14c94be7600c/api/pixel</TrackingUrl>
<Tag>phishing</Tag>
<Group token="doit">Division of Information Technology (DoIT)</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/doit</GroupUrl>
<AvatarUrl>https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="original">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/original.JPG?1727453227</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="large">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/large.png?1727453227</AvatarUrl>
<AvatarUrl size="medium">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/medium.png?1727453227</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/small.png?1727453227</AvatarUrl>
<AvatarUrl size="xsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxsmall.png?1727453227</AvatarUrl>
<Sponsor>Division of Information Technology (DoIT)</Sponsor>
<PawCount>1</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Thu, 22 Dec 2022 13:41:13 -0500</PostedAt>
<EditAt>Thu, 22 Dec 2022 13:42:58 -0500</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="38221" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/38221">
<Title>Phishing Scam Alert - Subject: IT Service Help Desk</Title>
<Tagline>UMBC would never ask "users are to verify there accounts."</Tagline>
<Body>
<![CDATA[
    <div class="html-content">
    <p>A new phishing scam is threatening to deactivate email accounts. This email is not from UMBC. <strong>Do not click this link.</strong></p>
    <p><br></p>
    <p>Here's what's being received:</p>
    <p><br></p>
    <p>"This E-mail is sent by the HelpDesk Expert for IT Support system for Mailbox notification and update purposes. We are conducting an email sweep upgrade due to our new login home page that is coming up soon for your better and faster server. So we are removing all unused email and registration of all active Student/Staff mail account to enable the University create new logins for our 2013/2014 students and staff. So all users are to verify there accounts.</p>
    <p><br></p>
    <p><strong>CLICK HERE:</strong> To go to verification page and follow the instructions on the popup page</p>
    <p><br></p>
    <p>IMPORTANT NOTICE: ACCOUNT OWNER THAT REFUSES TO VERIFY/UPGRADE HIS/HER ACCOUNT WILL LEADS TO YOUR ACCOUNT DE-ACTIVATION WITHIN 48 HOURS PRIOR TO THE URGENT THAT CONTAINED IN THIS SHEET.</p>
    <p><br></p>
    <p>Copyright@2013 Help-desk Technical Support Centre."</p>
    <p><br></p>
    <p><br></p>
    <p><strong>Again: Do Not Click The Link. If you already did, please change your password immediately.</strong></p>
    </div>
]]>
</Body>
<Summary>A new phishing scam is threatening to deactivate email accounts. This email is not from UMBC. Do not click this link.     Here's what's being received:     "This E-mail is sent by the HelpDesk...</Summary>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/38221/guest@my.umbc.edu/f7dbd1d0dd47e16dc9b7046b2ac56402/api/pixel</TrackingUrl>
<Tag>phishing</Tag>
<Tag>security</Tag>
<Group token="doit">Division of Information Technology (DoIT)</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/doit</GroupUrl>
<AvatarUrl>https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="original">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/original.JPG?1727453227</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="large">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/large.png?1727453227</AvatarUrl>
<AvatarUrl size="medium">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/medium.png?1727453227</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/small.png?1727453227</AvatarUrl>
<AvatarUrl size="xsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxsmall.png?1727453227</AvatarUrl>
<Sponsor>Division of Information Technology</Sponsor>
<ThumbnailUrl size="xxlarge">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/xxlarge.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="xlarge">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/xlarge.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="large">https://assets4-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/large.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="medium">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/medium.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="small">https://assets2-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/small.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/xsmall.jpg?1384191638</ThumbnailUrl>
<ThumbnailUrl size="xxsmall">https://assets2-my.umbc.edu/system/shared/thumbnails/news/000/038/221/c9ae486d4193a28218ebcf092e1a1659/xxsmall.jpg?1384191638</ThumbnailUrl>
<PawCount>84</PawCount>
<CommentCount>7</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Mon, 11 Nov 2013 12:48:18 -0500</PostedAt>
<EditAt>Fri, 25 Mar 2016 11:47:31 -0400</EditAt>
</NewsItem>

<NewsItem contentIssues="true" id="36838" important="false" status="posted" url="https://my3.my.umbc.edu/groups/doit/posts/36838">
<Title>Phishing Scam Alert: Fake Blackboard Notifications</Title>
<Tagline>Blackboard email notifications do not require you to sign in</Tagline>
<Body>
<![CDATA[
    <div class="html-content">
    <p>A new phishing scam is attempting to fool people into providing personal information by claiming that there is a Blackboard notification waiting for them, and provides a link for logging into Blackboard. <strong>Do not click this link.</strong></p>
    <p>Blackboard email notifications <strong>do not require you to sign in to Blackboard to read them</strong>, the information is provided in the email itself.  Always visit <a href="http://my.umbc.edu">http://my.umbc.edu</a> directly to log into Blackboard or by typing it in the address bar, or using your own bookmarks/favorites.</p>
    <p>Here is an example of the phishing email to watch out for:</p>
    <blockquote>
    <p>Good Morning,</p>
    <p>Your school has posted an important information regarding a course for you.</p>
    <p>You are required to immediately sign in to Blackboard Learn.</p>
    <p><span><span>Click here to sign in to Blackboard Learn</span></span></p>
    <p>Thank you.</p>
    <p>Blackboard Learn Notifications.</p>
    </blockquote>
    <p>Here is another example:</p>
    <blockquote>
    <p>Good Morning,</p>
    <p>An important course form has been posted to you on the Blackboard Learn System.</p>
    <p><span><span>Click here to confirm the form</span></span></p>
    <p>Thank you.</p>
    <p>Blackboard Learn Notifications.</p>
    </blockquote>
    </div>
]]>
</Body>
<Summary>A new phishing scam is attempting to fool people into providing personal information by claiming that there is a Blackboard notification waiting for them, and provides a link for logging into...</Summary>
<Website>https://wiki.umbc.edu/display/faq/Blackboard</Website>
<TrackingUrl>https://my3.my.umbc.edu/api/v0/pixel/news/36838/guest@my.umbc.edu/41839a0b7fb959b2549be619f82a9ad5/api/pixel</TrackingUrl>
<Tag>blackboard</Tag>
<Tag>phishing</Tag>
<Tag>security</Tag>
<Group token="doit">Division of Information Technology (DoIT)</Group>
<GroupUrl>https://my3.my.umbc.edu/groups/doit</GroupUrl>
<AvatarUrl>https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="original">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/original.JPG?1727453227</AvatarUrl>
<AvatarUrl size="xxlarge">https://assets1-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="xlarge">https://assets3-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xlarge.png?1727453227</AvatarUrl>
<AvatarUrl size="large">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/large.png?1727453227</AvatarUrl>
<AvatarUrl size="medium">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/medium.png?1727453227</AvatarUrl>
<AvatarUrl size="small">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/small.png?1727453227</AvatarUrl>
<AvatarUrl size="xsmall">https://assets2-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
<AvatarUrl size="xxsmall">https://assets4-my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxsmall.png?1727453227</AvatarUrl>
<Sponsor>Division of Information Technology</Sponsor>
<ThumbnailUrl size="xxlarge">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/xxlarge.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="xlarge">https://assets4-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/xlarge.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="large">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/large.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="medium">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/medium.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="small">https://assets4-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/small.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="xsmall">https://assets1-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/xsmall.jpg?1381428514</ThumbnailUrl>
<ThumbnailUrl size="xxsmall">https://assets3-my.umbc.edu/system/shared/thumbnails/news/000/036/838/b210d3789a96350fb4b8e79720ea5976/xxsmall.jpg?1381428514</ThumbnailUrl>
<PawCount>4</PawCount>
<CommentCount>0</CommentCount>
<CommentsAllowed>true</CommentsAllowed>
<PostedAt>Thu, 10 Oct 2013 14:09:44 -0400</PostedAt>
<EditAt>Fri, 25 Mar 2016 11:48:04 -0400</EditAt>
</NewsItem>

</News>
