Information Security Awareness campaigns – July Phishing Campaign: HP SCAN

As part of the Human Firewall Strength Procedure, to help increase and improve the online security and safety of KAUST personnel, we routinely carry out Information Security Awareness campaigns as an ongoing effort to strengthen the KAUST Human Firewall.

In our latest campaign, the following information might have alerted you that it was a phishing attempt: the email was sent from outside KAUST; ‘scanner@webshar.es’, not a KAUST-owned email/website.

If a hacker has knowledge that KAUST or most organizations use HP multi-function printers and attempts to send an email designed to mimic what the printer sends by default (an attachment with an empty body), the aim is to trick users to be curious to open the email. So remember, even if you have actually just scanned a document; be sure to view the sender details.

Emails were sent out to 3,804 community members, and almost 20.5% opened the attachment! If this was a real phish, all the machines used to open the attachment are potentially compromised. However, since we have anti-virus software installed on KAUST machines, we are still protected to an acceptable degree.

Phishing is defined as the attempt to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.

This campaign is a good reminder for us all in the KAUST community to refrain from clicking links that come from external email addresses before verifying their authenticity and to have up to date anti virus software.

We congratulate the following individuals, who were the fastest reporters for this phishing campaign:

May-18
Winners Reported within
Maya A Fritz 21 seconds
Faisal I. Alofesan 27 seconds
Imtiyaz Pasha 31 seconds
Jul-18
Winners Reported within
Karthikeyan Murugan 13 seconds
Paulo Prioste 17 seconds
Abdullah K. Wasfi 19 seconds

 

For any queries, feel free to reach out to us at: askinfosec@kaust.edu.sa

Good luck!

Related posts

Applications for 2025 KAUST M.S. and Ph.D. Programs Now Open

Plucking water from the air

2024 Plant Science Seminar