A-Level results - Students beware these university phishing attacks
New applicants at risk on A-Level results day
Students eagerly awaiting their A-Level results today have been warned not to fall victim to online scams after a new report found many of the UK's top universities could be putting students at risk of cyberattack by failing to implement proper online security.
Only one of the UK's top 20-ranked universities was found to have adequate protection against phishing attacks, which could allow hackers to spoof internal communications to trick victims into handing over personal details.
A recent report from security firm Proofpoint found that two-thirds of the top 20 univerisites were not properly protected against such attacks, which could affect new applicants awaiting their A-Level results later this month.
- LinkedIn emails are hiding phishing scams
- Netflix users hit by phishing scam
- One trillion phishing emails sent every year
Phishing
Proofpoint's research found that 65 percent of the institutions it surveyed had no published DMARC (Domain-based Message Authentication, Reporting & Conformance) record, making them more susceptible to cybercriminals spoofing their identity and increasing the risk of email fraud for students.
And with aound 235,000 prospectiver students awaiting their acceptance letters within the next few weeks, this could lead to criminals taking advantage.
Proofpoint added that its researchers also recently discovered that the education sector saw the largest year-over-year increase in email fraud attacks of any industry in 2018, rising 192 percent over 12 months for around 40 attacks per organisation on average.
"Email continues to be the vector of choice for cybercriminals," says Kevin Epstein, VP of threat operations at Proofpoint. “By not implementing simple, yet effective email authentication best practices, Universities may be unknowingly exposing themselves and their students to cybercriminals on the hunt for personal data."
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
"Institutions and organisations in all sectors should look to deploy authentication protocols, such as DMARC to shore up their email fraud defences. Cybercriminals are always going to leverage key events to drive targeted attacks using social engineering techniques such as impersonation and universities are no exception to this."
"Ahead of A Level results day, student applicants must be vigilant in checking the validity of all emails, especially on a day when guards are down, and attentions are focused on their future."
- Check out the best antivirus to help protect your business from the latest cyber threats
Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.