Email security

The email is still the number one gateway for malware infiltration by cybercriminals. Therefore, special attention should be given to assessing the credibility and plausibility of an email. Do not give cybercriminals the chance to gain access to all university and private data through you. If all technical protection systems have been circumvented, you are the last "rock in the surf" that protects the IT systems and thus your own information.

Email phishing is unfortunately a daily occurrence. The attackers usually try to redirect you to malicious websites via links in emails under the threat of account suspension. On these websites, deceptively modeled after the University of Applied Sciences Anhalt’s mail server, you will then be forced to enter your username and password.

Under no circumstances should you enter your login data there, otherwise the attacker can do everything with your access data that you can do!

The IT Service Center will never ask you to enter your user data including password via a link in an email!

Today's cyber attackers target their attacks specifically at their victims, thereby increasing the likelihood of a successful attack. They now research their victims to develop a tailored attack. They investigate LinkedIn profiles, what is posted on social media, or information that is publicly accessible or found on the dark web. They craft messages that appear to come from management, colleagues, or suppliers known to and working with the victim. They find out what hobbies the victim has and send him or her a message pretending to be from someone with similar interests. They find out that someone has recently attended a conference or just returned from a trip and then compose an email referring to that trip. Cyber attackers actively use other methods to send the same messages, such as sending an SMS or even calling directly.

Email phishing at the HSA Read more

Recommendations for Detecting Phishing Emails

These targeted attacks can also be recognized by you:

  • Do not let yourself be pressured
    • Is urgent action being suggested?
    • Are security policies being bypassed?
    • Are you being pushed to make mistakes?
  • Do not click on a link immediately
  • Check the plausibility of a message
    • Does the email make sense?
    • Could the claim in the message be true?
    • Does the message fit the time context?
    • Could the sender really have written this to you?
    • Would this person really ask you for this kind of help?
    • Is the sender even known?
    • Does the email address really exist?
    • Is your boss writing to you from a private email address?
    • Do the sender and email signature match?
  • Check the target address of the link through mouseover
  • Check the so-called "Who" area of a web address
  • Look at the grammar and language
  • Check the validity of a signature certificate (red seal)
  • Call the sender at a trusted number and ask for confirmation
Report Phishing Emails!

phishing@hs-anhalt.de 

Please forward these exclusively as an attachment. If you do not know how to do this, please contact the responsible administrator in your area beforehand. Otherwise, the phishing email will be distributed across the network, increasing the risk of other employees falling for it.

Also, use the new Outlook add-in for convenient reporting of phishing emails. Talk to your support administrator.

Take a look at the Phish-Bowl as well!
Do you want to send an encrypted email?
Flyer mit Tipps