Phishing
The word 'phishing' is a made-up word formed from the English terms 'password' and 'fishing' and literally means 'fishing for passwords'. The aim is to illegally obtain sensitive data from internet users and then use it for criminal purposes, which can cause significant harm to those affected. Login details for online banking are a common target, but passwords for e-mail accounts, online shops and social media platforms are also of interest to attackers. If this data falls into the hands of criminals, there is a risk that your identity will be stolen and that criminal offences may be committed in your name.
Phishing attack
The most common method used for phishing is the mass sending of e-mails with fake content. These e-mails are designed to look very similar to genuine emails from banks, online shops or other internet services. Recipients are often asked to update their details, for example because their credit card has expired, their password needs changing or their account information needs to be confirmed for security reasons. Attackers are banking on the fact that recipients will respond to the deceptively genuine-looking email, which purports to come from a service provider, thereby enabling them to intercept the data. The e-mail contains a link that the recipient is supposed to click on, which redirects them to a fake website. Sometimes, a form for entering details is included directly within the email itself. If passwords are entered there, the attacker can intercept them, gain access to the user’s account and take control of it, meaning you will no longer be able to access your own account.
Characteristics of a phishing e-mail and links to phishing websites
Impersonal or missing salutation
Online services or banks will always address you by name. If you are addressed as 'Dear Customer', you should be cautious. However, it is also possible that the attacker has previously found out your name, for example through a social engineering attack.
Urgent call to action
If you are asked to take urgent action within a specific timeframe, you should also be wary. This is particularly true if this request is accompanied by a threat. E.g.: "If you do not update your details immediately, they will be lost..." or "If you do not follow the instructions, your account will be blocked!"
The name and e-mail address do not match
In the case of external e-mails, the e-mail address appears alongside the name in the e-mail header. If the e-mail address and display name do not match, or if you do not recognise them, you should exercise caution.
E.g.: "Max Mustermann <asdglkjaälkj12235636378.asdf@asdf1234.gov.com>"
E-mails in a foreign language or with grammatical errors
Phishing e-mails are often translated from another language using a translation tool and are therefore written in broken German. Character set errors, such as Cyrillic letters or missing umlauts, are also an indication of dangerous e-mails.
Requests to enter personal details
A reputable bank will never ask you to enter your PIN, TANs, or similar details. If in doubt, please contact your bank or internet service provider by telephone.
Requests to open files
Never let unexpected e-mails trick you into opening an attached file. You should always be wary of e-mails containing file attachments and, if in doubt, check by telephone.
Requests to click on links or fill in embedded forms
Normally, your bank or other service providers will never ask you to click on links or to log in using your access details via a form contained within an e-mail. Should this nevertheless happen, access the website directly by typing the address into your browser. Ensure that the connection is encrypted (https://) and that valid certificates from the relevant provider are in place. Another example is the manipulation of the URL using Cyrillic letters. For instance, the Cyrillic 'a' looks very similar to the Latin 'a'. If a single letter is swapped, the result is a new URL that looks deceptively genuine.
Precautions
- Always be aware of potential risks!
- Be aware of the characteristics of phishing e-mails and phishing websites.
- Always keep your operating system and software up to date and install updates regularly.
- Use an antivirus programme and manually check any suspicious attachments for malware.
- If you are unsure whether an e-mail is malicious, verify its authenticity by contacting the sender by telephone.
- It is best to delete suspicious e-mails from your personal e-mail account immediately. If your work e-mail account is affected, please contact the relevant department straight away.
Contact
If you have received a phishing e-mail or even just suspect one, do not hesitate to contact the ITSC immediately. They will provide you with further instructions on how to proceed.
Würzburg location
Hotline
1st floor, room Z.1.07
Münzstraße 19
97070 Würzburg
Phone +49 931 3511-6260
Mon to Thu: 08:00-16:00
Fri: 08:00-15:00
Schweinfurt location
Hotline
Campus I
Room 7.1.07
Ignaz-Schön-Str. 11
97421 Schweinfurt
+49 9721 940-6262
Mon to Thu: 08:00-16:00
Fri: 08:00-15:00
