Universities Worldwide are the Target of Phishing Attacks by a Hacking Group Aimed at Stealing Research and Intellectual Property

Stu Sjouwerman | Oct 11, 2019

The Iranian hacker group dubbed Colbalt Dickens has hit over 60 universities around the globe attempting to steal credentials to provide access to sensitive data.

We’ve seen attacks this before, where universities doing research are the target of hacking groups and nation-states. This latest string of phishing attacks, according to security researchers at SecureWorks, is squarely focused on attempting to fool university users into providing credentials:

colbaltdickens01

Users are redirected to a spoofed logon page. Once a user gives up their credentials, they are passed to a valid university website.

Universities in 14 countries have been hit by this campaign, likely indicating that at least the phishing and credential collection portion of the attack is working.

According to SecureWorks, there is no signs that this attack is stopping anytime soon. So, universities should take immediate measures to better secure access to university resources by students and faculty. The implementation of multi-factor authentication for all users of the university network is a prudent step to protect against such attacks. Also important is the use of Security Awareness Training for university employees to help them understand their role in maintaining security, how attacks can occur, how to spot one, and what not to do should they come face-to-face with a spoofed phishing attack like the one above.

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.