Educause Security Discussion mailing list archives

Re: Unusual pattern of compromised accounts


From: Robert Smith <Robert.Smith () UCOP EDU>
Date: Fri, 26 Jan 2018 21:21:47 +0000

Hi Joe,

Please contact me off list.

Have an awesome day,

Robert Smith, CISSP, PMP
University of California Office of the President
(510) 587-6244 (o)
(510) 541-8103 (m)
robert.smith () ucop edu<mailto:robert.smith () ucop edu>


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Pollock, 
Joseph
Sent: Friday, January 26, 2018 1:17 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Unusual pattern of compromised accounts

Has anyone observed the following:


1.        A cluster of compromised accounts with no indication of a common factor such as clicking on a phishing link. 
Users have no idea how the compromise occurred.

2.       The culprits change the user's direct deposit authorization

3.       They may have been familiar with the Banner system.

4.       No other activity was observed.

We are looking for other indications,  such as compromised desktops,  but have found nothing as yet.

Please reply outside the list if you wish.

Joe Pollock
Network Services
The Evergreen State College

Current thread: