Dive Brief:
- The Research and Education Networking Information Sharing and Analysis Center issued an advisory Wednesday warning that colleges and universities are being targeted by hackers looking to reroute employee payroll direct deposits.
- According to the center, the spearphishing campaigns have focused on gaining access to direct-deposit information for the past year.
- The phishing attacks typically begin with an email that tries to trick the recipient into clicking on an official-looking link, where they are told to type in their university log-in information, InTheCapital reported.
Dive Insight:
Over the last 15 months, the targets have included Boston University, Texas A&M University, the University of Iowa, the University of Michigan and the University of Western Michigan. As a part of its advisory, the center recommended several defensive measures, including removing self-service direct deposit capabilities, adding two-factor authentication requirements and implementing back-end systems to check for suspicious changes in direct deposit accounts, such as those coming from unusual geographic locations.