All,
Attackers have gained access to email accounts from
outside of SUU and use the document sharing features of Google Drive and Office 365 (OneDrive) to share documents with our @
suu.edu email addresses.
Typical emails you will receive look like the following (with highlights to identify the email may be an attack):
Some indicators to look for to determine if the shared document is legitimate or not are:
- Is the shared document something I was expecting?
- Is the document shared by someone in our organization or an organization I work with frequently?
- Is there a comment leading me to believe someone at SUU is sharing a document with me (Mindy Benson example above)?
If you open the shared document, most of these attacks open a document in Google Drive or Microsoft OneDrive. The Shared Document typically isn't malicious, but leads you to believe you need to authenticate somewhere else. An example can be found below.
If you open a Google Document similar to the one above, please open the Help menu and select "Report Abuse" (see image below). This will notify Google of an attack and they will eventually review the document to remove it for Phishing.
If you followed the link in the Shared document, we have typically seen a Google Form, or a copied website looking like our MySUU portal login page. The Google Form example is below. Never submit passwords in a form.
You may also notice a "Report Abuse" link at the bottom of the form. Please report the abuse to Google as a phishing page if you already got this far in the phishing process.
If you have submitted your password in a Google Form (especially in the past month), please change your password immediately.
Feel free to reach out to our Help Desk (865-8200 or
support@suu.edu) if you need help changing your password.
Thanks,
Jim
--
 | Jim Shakespear | Director of IT Security INFORMATION TECHNOLOGY, SOUTHERN UTAH UNIVERSITY ELC 513 | (435) 865-8202 |