Categories: CyberCrimeSecurity

70 Percent Of UK Universities Have Fallen Victim To Phishing Attacks

A Freedom of Information (FoI) request has illustrated the cyber security threats facing UK universities, with 70 percent of respondents admitting to falling victim to a phishing attack.

For each of the 51 respondents to Duo Security’s FoI request, an individual was tricked into disclosing personal details via an email pretending to be from a trusted source.

The findings follow a recent warning from Action Fraud, the UK’s Fraud and Cybercrime Reporting Centre, of a phishing scam that is specifically targeting UK universities in the form of fake pay rise emails that direct victims to click on a malicious link.

University, Education © Sam72 Shutterstock 2012

University phishing

Twelve of the universities who responded said they had been attacked more than ten times in the past year, with seven (including Oxford University) reporting to have been hit more than 50 times in the same timeframe.

In terms of responses, only two universities said they were able to apply patches and upgrades to systems with 48 hours of the attack notification and four said it typically takes longer than 30 days to implement such updates.

“The challenge is that phishing attacks are increasingly sophisticated – a targeted spear phishing attack can be particularly difficult to spot – but they can ultimately compromise the security of the entire network,” said Henry Seddon, Vice President of EMEA at Duo Security.

“Universities need to be vigilant and practice good cyber security hygiene: security updates should be installed as soon as they are available as attacks delivered via phishing campaigns can specifically target out-of-date systems or unpatched software.

“Education is vital, so keep staff and students updated on the risks that phishing can pose – advising them not to click on any links or attachments that look suspicious.“

As has been well advertised, phishing attacks were one of the most prominent threat vectors in 2016, targeting organisations in all manner of industries.

Apple users, for example, were targeted with a text message scam timed to coincide with October’s clock change in the UK and the personal details of thousands of Seagate employees were stolen after an employee was tricked by a bogus email.

And the trend has continued in 2017, as phishing attacks have targeted the likes of Netflix, McDonald’s and even the Saudi Arabian government.

Quiz: Cyber security in 2017

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

NASA, Boeing To Begin Starliner Testing After ‘Anomalies’

American space agency prepares for testing of Boeing's Starliner, to ensure it has two space…

20 hours ago

Meta Launches Friends Tab, As Zuck Touts ‘OG Facebook’

Zuckerberg seeks to revive Facebook's original spirit, as Meta launches Facebook Friends tab, so users…

1 day ago

WhatsApp Appeal Against EU Fine Backed By Court Advisor

Notable development for Meta, after appeal against 2021 WhatsApp privacy fine is backed by advisor…

2 days ago

Intel Board Shake-Up As Three Members Confirm Retirement

First sign of shake-up under new CEO Lip-Bu Tan? Three Intel board members confirm they…

2 days ago

Trump’s SEC Pick Pledges ‘Coherent’ Crypto Rules

Trump's nominee for SEC Chairman, Paul Atkins, has pledged a “rational, coherent, and principled approach”…

2 days ago