Immediately change your Syracuse University (NetID) password. To do so, visit the NetID self-service page. Additional instructions and details can be found on the Password Change FAQ.
Immediately change any passwords for any accounts indicated in the phishing message, if other than your Syracuse University account.
You should not be using the same password you use for your NetID anywhere else. If you do, change any passwords for any other accounts to different and unique passwords. |
Attackers may attempt to add email rules to your account in an attempt to hide their activity from you. To do this, they often set up rules to forward and/or delete email entirely or strategically from key individuals or University offices such as ‘ITS’, ‘Bursar” or ‘Payroll’.
Instructions to check inbox rules can be found on the Securing SUMail Account After Security Lock page.
Please take note of what those rules are and provide them to the Information Security Department (see Step 4).
Attackers may attempt to change information related to your account including personal and financial information. Users should verify the following information has not been altered:
The ITS Information Security Department depends on the Syracuse University community to help detect and protect against phishing attacks. Taking a brief moment to send us an email may help protect many others from the attack. Simply forwarding the message to ITSecurity@listserv.syr.edu is helpful, but providing additional information as shown below will help us better protect other individuals and your access.
Have you already changed your password? Letting us know that you’ve already changed your password may prevent us from locking your account if we detect your original password being compromised.
Provide the original email headers. Headers contain detailed mail routing information that we can use to investigate the attack. Instructions on obtaining the headers can be found on the Answers “Sending Email Headers” page.
What information you provided. Did you provide your SSN? Your date of birth? Your name? Your NetID/Password? We don't need the actual information, but letting us know the type of information you entered helps us to understand the scope of the attack.
The content of your inbox rules. If you found malicious rules (rules you did not setup) in your email box, letting us know what those were will help us detect other accounts that have been compromised.
Several external resources are available to reduce threats to your identity in the event you have provided personal information to attackers or you simply want to be aware of identity related protections. They include but are not limited to:
For ongoing account protection, be proactive and aware regarding the following:
For assistance with the information above, contact the ITS Help Desk at 315-443-2677, help@syr.edu, or by stopping into 1-227 CST. Stay up-to-date on the latest phishing activity on the ITS website.