London Metropolitan University Student Zone Online

Cybersecurity

Phishing and malware received through email is one of the most common information security threats faced by the University. Nobody is immune from these threats.
 
The London Met IT department has added some extra information to most emails sent and received from senders not using a London Met email address.
 
This extra information appears at the start of external emails and will offer some information to help you assess if the email is a possible security threat or not. This kind of email tagging is becoming more common so some of you may have encountered it at other institutions. IT has adopted this change to support and increase personal privacy and organisational cybersecurity. 
 
If you feel a partner institution or system should not be included in this, please log a ticket in the IT self-service portal and someone will be in touch to discuss this with you. Please note personal, individual email addresses will not be whitelisted. 
 
If you have any questions please contact Brian Brackenborough Head of Cyber Security (b.brackenborough@londonmet.ac.uk) or Liz McNaughton, Head of Service Management, (e.mcnaughton@londonmet.ac.uk).

For any Cyber Security issues or questions, please email cybersecurity@londonmet.ac.uk quoting your ticket reference number.  

What is phishing?

Phishing is a type of online identity theft usually, claiming to be from an organisation that you may trust, that uses email and fraudulent websites to trick you into sharing your information such as credit card numbers, passwords, account data or other valuable information.

Spam is unwanted, junk email, typically sent to large numbers of people, for the purposes of advertising, phishing, spreading malware, etc.

How to spot phishing

Email fraud that targets university staff and students is on the rise. It is becoming increasingly sophisticated and hard to identify.

We have systems in place to limit how many fraudulent emails get through and to minimise the impact where possible. However, some emails will always get through, so it is vital that you remain alert to potential threats and take responsibility for the security of your University computing and email accounts.

Below are some tips for spotting phishing attempts and email scams.

  • Be wary of emails that ask you to validate or verify your account.
  • Phishing emails tend to be poorly written and may include spelling mistakes and odd formatting.
  • Look out for emails that have a sense of urgency and imply you might lose access to your account or those with threatening tone and content.
  • They may appear to be from someone you know or an official source at the University.
  • Be wary of links in emails. Is the destination the same as the link you see? Try hovering over the link to check.
  • The email starts with an unusual or generic greeting such as ‘Dear valued customer’.
  • A fraudulent email may contain attachments, which could include .exe files.
  • A request for personal information such as your username, password or student loan details. The University will never ask you for a username or password. 
  • Remember, if it seems too good to be true, it probably is.

What action should you take?

  • Never respond to emails that ask for your password or other sensitive information.
  • Never click on or open suspicious links or attachments.
  • If you're taken to a login page or website, never attempt to log in or enter your personal information.
  • If it appears to be from someone you know contact the original sender by telephone or create a new email to ask them if the email is genuine.

I think I have fallen for a phishing scam, what do I do?

If you or anyone you know falls for a phishing scam, you should:

What to do if your account has been compromised or hacked.

Cybersecurity Hub

In the case of a major cyber incident, the university's web pages and systems may be not be accessible.  Staff and students can now visit our externally hosted CyberSecurity Hub in this instance, where up to date information will be shared. Please save the url in your favourites for reference in case of any emergency.

Top Tips for Staying Safe

As part of Cybersecurity Awareness Week we spoke to researchers from London Met's Cyber Security Research Centre and asked them to provide expert advice for students and staff around cybersecurity.

Cyber Security: What Students Need to Know 

Your account. Your information. Your money. 

Starting or returning to university means lots of messages, new systems, deadlines, payments and people contacting you. Cyber criminals know that too. They target students with fake emails, messages, websites, jobs, payment requests and login pages. 

You don't need to be a cyber security expert to protect yourself. There are a few things you should know. 

1. Protect your University account 

Your University account is valuable. Someone who gets access to it may be able to read your email, access your files, impersonate you or use your account to attack other people. 

  • Never share your password. 
  • Never give anyone an authentication or verification code. 
  • Never approve an MFA or authentication request unless you are actually trying to log in. 
  • Use a different password for your University account and your personal accounts. 

2. Think before you click 

Be cautious when an unexpected email, message or QR code asks you to log in. A fake login page can look almost identical to the real thing. 

If you're unsure, don't use the link. Open your browser and go to the University website or service yourself. 

3. Watch out for scams aimed at students 

Criminals know what students are interested in and what might make you act quickly. Be particularly careful about unexpected messages concerning: 

  • Student finance 
  • Tuition fees or refunds 
  • Accommodation 
  • Part time jobs 
  • Visas 
  • Scholarships or grants 
  • Parcel deliveries 
  • Discounts and offers 
  • Unexpected payments 
  • Problems with your University account 

4. Urgency should make you more careful, not less 

Attackers often want you to act before you have time to think. 

Examples include: “Your account will be closed.” “Payment required today.” “Your parcel couldn't be delivered.” “Your student finance has been suspended.” “You have 30 minutes to verify your account.” 

Take your time. If something is genuinely important, you can verify it independently. 

5. People online aren't always who they claim to be 

Email addresses, caller IDs, websites and social media accounts can be faked. Someone may also have taken control of a genuine account. 

AI is making convincing fake messages, images and voices easier to create. 

If somebody asks for money, passwords, authentication codes or something unusual, verify who they are another way. 

6. Be careful what you share 

Think before uploading University work, research, personal information or information about somebody else to websites, apps, file sharing services or AI tools. 

Once information has been shared with an external service, you may no longer have full control over it. 

Use University approved services for University information and follow any guidance provided for your course. 

7. Keep your devices protected 

  • Install updates when they're available. 
  • Use a screen lock, PIN, password or biometrics. 
  • Don't leave devices unattended in public places. 
  • Only install software and apps from sources you trust. 
  • Be cautious about software offered free through unofficial websites, particularly cracked or pirated software. 

Something gone wrong? 

Tell us. 

Maybe you: 

  • Clicked a suspicious link 
  • Entered your password into a website 
  • Approved an MFA request you shouldn't have 
  • Opened a suspicious attachment 
  • Think somebody has accessed your account 
  • Lost a device 
  • Sent information to the wrong person 
  • Have seen something that just doesn't look right 

Don't try to investigate it yourself and don't wait to see what happens. 

The sooner you tell us, the more we can do to help. 

How to report a cyber security concern 

You can report a cybersecurity concern by sending an email to cybersecurity@londonmet.ac.uk or you raise a ticket to the cybersecurity team using https://lmu.freshservice.com/  

 

One thing to remember 

If something online doesn't feel right, don't let someone rush you into doing something. 

Check it independently or ask us for help.