WEBVTT

00:00:01.120 --> 00:00:04.040
Information from the University
Computer Centre

00:00:04.360 --> 00:00:07.960
Attempted fraud through phishing

00:00:07.960 --> 00:00:11.360
Samu is very enthusiastic
about his studies.

00:00:11.720 --> 00:00:15.640
But one day he receives an e-mail
from the University Computer Centre

00:00:15.640 --> 00:00:19.840
informing him that his account
has been blocked and he is shocked.

00:00:19.920 --> 00:00:21.760
Has he been deregistered?

00:00:22.520 --> 00:00:24.240
After reading the message again

00:00:24.240 --> 00:00:27.960
he notices mistakes in the message
and contacts the URZ

00:00:28.080 --> 00:00:30.760
and indeed,
the e-mail is a phishing attempt.

00:00:31.440 --> 00:00:36.240
He asks the URZ support team to explain
the fraudulent scam in more detail.

00:00:36.600 --> 00:00:39.600
Phishing is a common
method of deception used

00:00:39.600 --> 00:00:41.920
to steal sensitive personal data.

00:00:42.680 --> 00:00:46.480
Scammers pretend to be
a trustworthy communication partner

00:00:46.560 --> 00:00:49.760
by imitating
reliable people or institutions.

00:00:51.360 --> 00:00:52.880
And this is how it works:

00:00:52.880 --> 00:00:57.240
University members receive a supposed
e-mail, for example, from the URZ.

00:00:57.480 --> 00:01:01.280
The content of the e-mail
usually includes blocking the account,

00:01:01.520 --> 00:01:04.280
a request to update user data, or similar.

00:01:04.760 --> 00:01:07.320
The e-mail also contains a link
through which

00:01:07.320 --> 00:01:10.520
the threatened scenario
apparently can be averted.

00:01:10.920 --> 00:01:14.760
The link leads to a URZ
page where users can log in.

00:01:15.920 --> 00:01:19.200
Both, the e-mail and the website
look official.

00:01:19.400 --> 00:01:23.240
However, both are
unfortunately well-made fakes.

00:01:23.640 --> 00:01:26.280
The aim: as soon as users input

00:01:26.280 --> 00:01:29.760
data on the website,
the scammers access it.

00:01:30.280 --> 00:01:34.120
The URZ is already sorting out
most of those e-mails.

00:01:34.440 --> 00:01:39.680
Unfortunately, new methods are constantly
appearing which fall through the filters.

00:01:40.280 --> 00:01:43.920
Therefore, the only thing that helps
is to be attentive.

00:01:44.280 --> 00:01:48.080
Recognizable signs are
typos and grammatical errors,

00:01:48.360 --> 00:01:51.480
impersonal salutation,
such as „Dear User“,

00:01:51.800 --> 00:01:55.640
the build-up of pressure
like „Act within 12 hours“,

00:01:55.960 --> 00:01:59.800
and messages sent shortly
before the weekend or public holidays

00:01:59.920 --> 00:02:02.920
so that the real support team
is no longer available.

00:02:03.360 --> 00:02:07.400
The senders of e-mails can be forged,
which is why the URZ.

00:02:07.440 --> 00:02:11.280
has its own digital certificate
that should be observed

00:02:11.600 --> 00:02:15.040
In times of ChatGPT and DeepL
error-free e-mails

00:02:15.040 --> 00:02:17.040
are no guarantee of security.

00:02:18.120 --> 00:02:20.840
A look at the linked URL
helps as well.

00:02:21.040 --> 00:02:25.120
The official address is:
tu-chemnitz.de

00:02:25.320 --> 00:02:27.480
Are there the slightest deviations here?

00:02:27.720 --> 00:02:30.600
If in doubt, Samu does not
use the link,

00:02:30.640 --> 00:02:33.000
but goes to the website independently.

00:02:33.800 --> 00:02:35.640
Especially perfidious:

00:02:35.640 --> 00:02:40.560
If trusted persons contact Samu
with unusual requests and send files,

00:02:40.720 --> 00:02:44.720
this is probably done from accounts
that have already been hacked.

00:02:45.240 --> 00:02:49.160
Samu should therefore
only open file attachments if he is sure

00:02:49.200 --> 00:02:51.840
or he could ask the person
by other means.

00:02:52.440 --> 00:02:54.520
If he has fallen for a scam

00:02:54.840 --> 00:02:57.440
he first changes all of his passwords,

00:02:57.440 --> 00:03:01.240
and then contacts the URZ
support team immediately.

00:03:01.240 --> 00:03:05.160
Next, he warns those around him
about his hacked account.

00:03:06.360 --> 00:03:10.440
How to forward suspicious e-mails
completely to the URZ support,

00:03:10.640 --> 00:03:16.720
as well as further information on current
scams can be found on the URZ website at:

00:03:16.720 --> 00:03:19.800
mytuc.org/phishing

00:03:20.320 --> 00:03:22.760
Samu can also do
a phishing self-test there.

00:03:23.400 --> 00:03:28.240
www.tu-chemnitz.de/urz

