Table of Contents

Spam, Phishing and Malware

Motto:

  1. Quick and automate reaction makes troubles.
  2. Do not accept what message suggests, until you are perfectly sure you understand the intentions.
  3. Do not belive the sender's identity until you really verify it (check sender’s email address closely).

Bonuses:

Good article about clicking links in emails (phishing etc.)

How and why Thunderbird block remote content


See also “Dealing with malware, spam, suspicious content” in separated CERGE-EI Wiki article (details about security measures applied to incoming emails)

and "Spam fiters at CERGE-EI" (describing chain of email filters for incoming traffic)


Types of attacks, its danger and adequate reaction:

spam

[Classification: POTENTIALY DANGEROUS]

hoax

[Classification: ANNOYING]

phishing

[Classification: PRETTY DANGEROUS]

spoofing

[Classification: DANGEROUS]

malware

[Classification: DANGEROUS]

ransomware

[Classification: THE MOST DANGEROUS]

What to do, if you are uncertain about email (possible cyber attack)

  1. Thing first, check all circumstances, ask in doubt (IT, colleagues, sender,…).
  2. Do not allow the time presure effect, think twice. postpone the action (back to step 1 eventually :-)
  3. Only if you are absolutely sure, continue with an action suggested in email (settings review, password change etc.)
  4. In case of any suspicion at any time, share it with IT (including all details).
  5. If you think you have compromised your password or account in any way, change the password ASAP and inform IT (compulsory).

In any doubt, do not hesitate to ask helpdesk@cerge-ei.cz. Please prepare complete documentation, timeline, addresses, raw text of message (see wiki - problem reporting)