Pages

Showing posts with label email fraud. Show all posts
Showing posts with label email fraud. Show all posts

Tuesday, July 28, 2026

Pension Payments at Risk - Part 4

Blog readers may recall our earlier postings on a pension fraud involving UCRP. The fraudsters used persuasive tactics to gain access to various retiree pension accounts and diverted their payments.*

We now have a more complete understanding of the various failures that allowed the fraud to occur courtesy of Professor-Emerita Amy Block Joy of UC-Berkeley. (She is also chair of CUCEA.) Her "case study" of the fraud is at:

https://www.acfe.com/acfe-insights-blog/blog-detail?s=direct-deposit-social-engineering-case-study.

Excerpt: Investigations found that this scheme resulted in 345 cases of suspected fraud. A total of $885,939 in fraud was intercepted and stopped across 47 accounts, with $154,507 in funds lost in 10 of them. (The Pension Office later reimbursed all members who endured losses to their accounts.) 

If you are receiving a UC pension, you should check each month that the appropriate funds were transferred to your bank.

===

*Our earlier postings on this pension fraud are at:

https://uclafacultyassociation.blogspot.com/2026/02/pension-payments-at-risk-part-3.html; https://uclafacultyassociation.blogspot.com/2026/01/pension-payments-at-risk-part-2.html.

Saturday, July 25, 2026

Breach


 

This data breach appears to be confined the UCLA Health, unless it wasn't. 

Tuesday, July 21, 2026

Don't Respond

It looks innocent enough: an electronic invitation to an event, seemingly sent by someone you know. But when you start to respond, it begins to ask you for things such as the password to your email account. That's a big no-no. Do not supply such information. It likely means that your contact has been hacked. And you will be, too, if you supply information.

What you can do is to contact the person supposedly sending the invitation, indicate you think a hacking has occurred, and advise them to let all their contacts know.  

Monday, July 20, 2026

When is it over? - Part 2

Remember the Canvas hacking that brought instruction at various universities including UCLA to a halt?

From Inside Higher Ed: Two months after Instructure made a deal with hackers to salvage troves of stolen user data, the company—which owns the popular learning management system Canvas—may have another breach on its hands. And this time, the incident is delaying Instructure’s efforts to be transparent with its customers about their compromised data. 

In May, a criminal extortion group known as ShinyHunters twice hacked Canvas and claimed that it gained access to the personal identifying information of 275 million people across 9,000 institutions. At the time, the company said the leaked information included names, email addresses, student ID numbers and user messages, but it “found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.” 

In the aftermath, Instructure CEO Steve Daly vowed to be “transparent about what happened” and provide K–12 schools and higher education institutions “with information as quickly as we responsibly could.” Over the past two months, Instructure has worked “to conduct a detailed forensic review of the data involved in this incident,” Daly said in a memo last week. On Tuesday, the company was set to deliver to institutions the first wave of data related to the breach. Instead, Daly said Tuesday that the company is “pausing data delivery out of an abundance of caution” after learning that “the third-party platform we’ve selected to deliver your data may have been subject to a security threat.” ...

Full story at https://www.insidehighered.com/news/quick-takes/2026/07/16/another-security-threat-canvas.

Thursday, July 9, 2026

Avoid Hacking: Just say no

The New York Times recently ran an op ed titled "It’s Inevitable — You’re Going to Get Hacked." Here is an excerpt:

I run a public relations company, and there is one type of crisis no amount of planning can allay. It might start like this: One of my clients — imagine the founder of an A.I. start-up — receives notice that her iCloud account is about to be deleted because the payment method is no longer valid. Her assistant, who has access to her devices, calls her so he can update the payment method, and asks for her two-factor authentication code. The founder reads off the code. Moments later she’s locked out of her iCloud. Her text messages, photos, her videos, voice memos and notes-to-self — all stolen. The founder calls me in a panic.

How could this happen? The founder’s passwords could have been compromised and listed on the dark web. With the help of artificial intelligence, the hackers can send the fake nonpayment notice, clone her assistant’s voice using videos posted on Instagram and enter the two-factor authentication code to break into her iCloud account. Then, they could demand a Bitcoin ransom to return the trove of personal musings, sexts and photos, perhaps some sans clothes.

This scenario is not as far-fetched as it sounds. Apple has some of the strongest security measures in tech and is constantly innovating new defenses, but in recent months it has repeatedly warned its customers of sophisticated scams. Gmail break-ins are proliferating. Hackers are subjecting even everyday people to embarrassing leaks. Once they get into your iCloud account, they could have access to your entire digital history dating back to your first iPhone...

Full op ed at https://www.nytimes.com/2026/07/02/opinion/hacking-ai-leaks-shame.html.

These scenarios involve people giving away information. If you get an email, text, or phone message asking for anything - such as a password - DON'T GIVE IT, no matter how urgent the request seems to be, or how trustworthy the messenger seems to be. DON'T DO IT. Just say NO. And use multifactor authentication where it is offered.

Sunday, July 5, 2026

Ignore - Report - Delete

Click on image to clarify
===
Just a reminder that unsolicited offers to create a (presumably flattering) Wikipedia page for you should be ignored. You can report them to Wikipedia by forwarding them to:

paid-en-wp@wikipedia.org

If you do so, you will receive an email from Wikipedia saying:

Thank you for reporting this. There are many paid editing companies out there that look through recently-declined drafts or who contact people with public careers and contact information (like academics and professors) to send this kind of solicitation. Very few of them comply with Wikipedia's paid-editing policies, most are outright scams, and none are endorsed by Wikipedia, no matter what they may say. Feel free to ignore future emails like this, and we recommend marking them as spam.

Sincerely,

331dot

The conflict of interest volunteer response team

Monday, June 22, 2026

When is it over?

From Higher Ed Dive: Dozens of higher education institutions may have been hit by another attack from the cybercrime group behind the May hack against Canvas, according to the Google Threat Intelligence Group and cybersecurity firm Mandiant.

From May 27 and June 9, the group ShinyHunters potentially gained access to the systems of over 100 organizations by targeting the Oracle PeopleSoft software suite. A majority of them are based in the U.S., and 68% are within the higher education sector...

ShinyHunters twice gained unauthorized access to Instructure’s Canvas learning management system last month, disrupting final exam season at colleges nationwide...

Colleges are a prime target for cybercriminals, both because they hold vast troves of student and employee data and because their systems typically have a massive number of users that turn over regularly...

Full story at https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/.

Thursday, June 18, 2026

Another Scam

Another scam. Delete. Don't respond.

Wednesday, June 10, 2026

Let's not forget about Canvas

Remember when the various Canvas plans were hacked and many higher ed institutions, including UCLA, came to a halt?

EdSource has information on what it costs. A bigger issue is that the hacking of Canvas creates questions about dependence on that company, data security, etc.

...Last month, a data breach by hacker group ShinyHunters upended access to Canvas and led to service disruptions around the world at thousands of schools. California’s public colleges and universities were preparing for exams at the moment when Instructure was held ransom: pay up, or terabytes of private data, including student and staff records, would be leaked, the group threatened...

[State] Sen. Melissa Hurtado, a Bakersfield Democrat, has called for a legislative audit into Canvas. “The Canvas breach exposes the growing risks of concentrating massive amounts of student records, academic systems and institutional operations into a single platform,” she said.

Full story at https://edsource.org/2026/how-much-do-california-colleges-and-universities-spend-on-canvas/759415.

Tuesday, June 9, 2026

Yet Another Scam


Delete it. Don't respond.  

Friday, May 29, 2026

Latest Scam


If you are a Southern California Edison (SCE) customer, you might have found this card in your mailbox. It is not from SCE. It is not an official anything. When yours truly typed the phone number shown into Google, up came a scam warning that a similar card had been distributed up north to PG&E customers. There was also a scam warning about cainitiative.com, a web address on the card. (I don't know if DWP customers have gotten similar cards.) 

Someone is trying to sell you something - or worse. Discard the card.

Wednesday, May 13, 2026

Paid Off

Remember last week's hacking into Canvas that caused an interruption in availability of Bruin Learn?

It turns out that Instructure, the supplier of Canvas, paid a ransom to get its data back, presumably thereby protecting all the students and faculty in the various universities that use Canvas. From Inside Higher Ed:

Instructure has paid a ransom to a gang of cybercriminals that have twice hacked the company’s learning management system, Canvas, over the past week and a half. nstructure has paid a ransom to a gang of cybercriminals that have twice hacked the company’s learning management system, Canvas, over the past week and a half. According to an update published by the education-technology company Monday night, the deal means that the hackers have returned the compromised data of some 275 million users across more than 8,800 institutions...

Full story at https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers.

Monday, May 11, 2026

The Hacking - Part 2

From the Daily Bruin: UCLA restored access to Bruin Learn on Saturday evening, two days after a cyberattack took down the learning platform. ShinyHunters, a criminal extortion group, breached Canvas, which hosts BruinLearn, Thursday afternoon. It threatened in a message posted to the website that it would release universities’ data if Canvas’ parent company, Instructure, did not negotiate a settlement...

Full story at https://dailybruin.com/2026/05/09/ucla-restores-access-to-bruin-learn-2-days-after-cyberattack.

There doesn't seem to have been a public assessment of issues that arise from being dependent on an outside vendor whose size alone invites cyberattacks.

Friday, May 8, 2026

The Hacking

The Bruin Learn system that supports instruction at UCLA is part of the Canvas system - and Canvas has been hacked by a group called "ShinyHunters." Information can be found at:

https://databreaches.net/2026/05/07/developing-shinyhunters-hacks-instructure-again-canvas-down/.

From an email to a particular UCLA school:

I wanted to give some guidance around the Bruin Learn outage announced below. As you are likely aware, the outage appears to be connected to a disruption to one of UCLA's technology vendors, which is used by hundreds of universities. Many schools are experiencing outages. However, our students and you likely care most about when service will be restored, and how you can best minimize the effect of the outage while it is ongoing.

On the first question, we simply don't know when service might be restored. As central campus updates us on the situation, we will let you know what we learn. Given this uncertainty, we advise that you plan on alternative arrangements for activities that you planned to carry out on Bruin Learn.

  • To that point, we recommend you to be flexible in your approach. Some simple approaches that might help:
  • We recommend you not try to recreate Bruin Learn/Canvas on another site, and keep things simple. This may mean making adjustments to certain aspects of your class.
  • You can email the class directly on MyUCLA, much like a Bruin Learn announcement. You can also use MyUCLA to download a spreadsheet that includes the email addresses of all students in your class.

Students will appreciate frequent communication via email reiterating any adjustments you make to the class because of the outage. Please feel free to make your reminders repetitive, so that students are more likely to see them. You may want to let your students know your communications may be repetitive, but that you want to make sure everyone understands how the class will adapt to the outage...

We know this is disruptive, and the University is working very hard to restore access as soon as possible. Thank you for your flexibility as campus works through this challenge. We’ll keep you posted as we hear more...

Yours truly remembers the days when we used blackboards and chalk, and students got their readings from a thing called "the library." No one could hack into them. 

Friday, April 24, 2026

Caution Advised

There have been reports of phone calls that purport to be from Navitus, the company that manages drug costs for some of UC's health insurance plans.

If you get a call that indicates a problem with your prescriptions, the best thing to do is to avoid responding directly. The general number for Navitus for those covered by its plan is 844-268-9789. If you get a message on your voicemail, call that number - not the number that may have been indicated in the phone call message - and ask if there is really a problem. 

If you answer the original call, do not provide any information to the caller. Call back at the 844 number above.

Thursday, April 16, 2026

Wikipedia Solicitations - Part 3 (flood)


The flow of Wikipedia solicitations - such as the one below - seems to be turning into a flood. Again, if you get one, you can either delete it or report it to Wikipedia at paid-en-wp@wikipedia.org. What you should not assume is that you will get what you are paying for if you engage someone who sends you a solicitation to write or enhance a Wikipedia entry.


Tuesday, April 7, 2026

Don't Click!


It may be tax time, but if you click on this fraudulent email which has been sent to some UCLA addresses, you will have a taxing experience.

Friday, April 3, 2026

Wikipedia Solicitations - Part 2

We have previously posted about solicitations from Wikipedia "editors" to write a nice page for you.* Such solicitations inevitably involve paying for the service. They may be outright scams. Or they may involve claims that seem to suggest that whatever they write is what will appear on Wikipedia.

If you get a solicitation such as the one reproduced at the bottom of this post, the best advice is not to respond and delete the message.

You can also report them: paid-en-wp@wikipedia.org

====

*https://uclafacultyassociation.blogspot.com/2026/01/wikipedia-solicitations.html

===

It's worth also repeating that Wikipedia is OK as a source for non-controversial information. Controversial political topics are another matter. Note also that if you ask an AI source about a controversial issue, it is likely to reproduce Wikipedia interpretations as if they are facts. Caution advised.







 

Monday, March 16, 2026

There's one thing you can be sure of...

...Contrary to what it says, this message did not come from "your health plan." Do not click. Delete.

Wednesday, March 11, 2026

Lucky Me: Second Time I've Won!

It's one thing to win a prize. But it's really super to win a certified prize.