Following various malicious emails that have been doing the rounds over the last few days, here’s a little information.
The attack basically uses social engineering, i.e tricking people. The email contains no viruses or malware, simply clicking the link will do nothing to your device or computer, this attack is purely relying on human behaviour to succeed.
It works like this;
- An email is sent to a user from someone they know with a familiar subject line and a button to click usually labeled ‘Read email‘.
- When clicked the button opens a webpage with the museums logo and a box to enter their password.
- The user enters their password in to the box.
- The attacker then uses the password to log into their email account and send more emails out, and so the cycle continues.
There are just two simple rules that will protect you (and the museum) from the majority of attacks on both your work and personal systems.
- Do not click links in unfamiliar or unusual emails
- NEVER EVER EVER enter your password to any page you’ve arrived at from a link in an email.
Be rest assured in the specific email that’s been doing the rounds recently clicking the button/link in the email alone will not do any damage, it is entering the password that causes problems.
Although we use various tools and methods to protect the museums systems and the majority of malicious emails it’s very hard for us to block every single one and our strongest protection comes from you.
As far as we can tell the attack primarily targets corporate users such as the museum and not personal accounts, although this may change and there are many similar emails around so stay vigilant.
Top tip: If you ever feel any of your personal accounts have been attacked in any way, from any source, change your password, this will stop the large majority of attacks.
Remember passwords should be unique (never use the same password on multiple sites), should be made up of letters, numbers and symbols, and be of decent length (over 12 characters). Short phrases make really good passwords that are easy to remember.
If you have any question of queries please don’t hesitate to get in touch via your line manager.