Warning: Disclosure of your email account details

Posted on January 04, 2016

This is a serious warning to users not to respond, under any circumstances, to any email requesting you to confirm your sign-on details for any UP system by replying to an email or clicking on a given link. In particular, you should NEVER respond to any email message requesting you to provide your email user name and password for any of the following (fake) reasons:

  • to upgrade or maintain your email account
  • to increase your mailbox size
  • to obtain new services
  • to prevent your email account from being deleted

 

A staff member who responded to such a message during the past week had to carry the following consequences:

  • Her email account was used to distribute spam.
  • More than 58 000 addresses were added to her Frequent Contacts address list in GroupWise.
  • Her mailbox was flooded with about a thousand messages of undelivered mail.
  • ITS had to clear her Frequent Contacts address list.
  • Windows had to be reinstalled to ensure that no undetected malware remained on the system.

Another possible consequence is that the UP domain may be blacklisted because such a huge volume of spam was sent from it, resulting in other mail servers refusing mail sent from up.ac.za.

Users must take note that Windows will be reinstalled on any compromised computer (or if a strong suspicion exists that the computer may have been compromised), for the protection of the user as well as the UP user community. This is necessary because it is extremely time-consuming and virtually impossible to ensure that all malware has been detected and removed after such a breach. Copies of data created on such computers after the breach are not safe and cannot be reloaded. Users must therefore take care to back their data up regularly, including their GroupWise archives, as a precaution against such an event.

See the following documents for further details on how to recognise scams and how to make backups:

  • How to check if a message is a scam: https://www1.up.ac.za/cs/groups/public/@public/documents/document/mdaw/mdiz/~edisp/uppr023975.pdf
  • How to back up my desktop/laptop computer:

http://www1.up.ac.za/cs/groups/staff/documents/document/mdaw/mda5/~edisp/uppr009612.pdf

 

Erica Ferreira

IT Risk and Compliance Manager / IT Risiko- en voldoeningsbestuurder

IT Services / IT Diens

University of Pretoria / Universiteit van Pretoria

Tel: 012 420 5462

- Author Erica Ferreira

Copyright © University of Pretoria 2025. All rights reserved.

FAQ's Email Us Virtual Campus Share Cookie Preferences