Tower

UF IT Security Alert

11-2-2005

Scam emails were sent only Saturday and Sunday, 10-29-05 and 10-30-05. The malicious web site is no longer accessible.

10-31-2005

An email scam is being targeted at University of Florida faculty, staff, and students. The email appears to be from the Campus Credit Union. It references a problem with your account due to an unauthorized ATM transfer. The email lures you to a web site to correct the account problem, but the link in the email takes you to a malicious website intended to steal your Campus Credit Union account and password. If you received one of these emails, do NOT follow the link. Please forward the email showing full headers to abuse@ufl.edu.

Here is a sample of the malicious email:

Subject: Temporary limited your access to Campus USA Credit Union features !
Date:    Sat, 29 Oct 2005 18:05:12 +0200
From:    Campus USA Credit Union <prevent@campuscu.com>

member FDIC
This message contains graphics. If you do not see the graphics, click
here to view <http://que.capmuscu.com/asp/USERS/Common/Login/NetLogin.htm>.
Or, copy
http://sdm3.rm04.net/servlet/MailView?ms=MjQxMzM4S0&r=NTcyMjAxOTI5S0
into your browser.

Dear Campus USA Credit Union Valued Member,

We recently reviewed you account, and we suspect an unauthorized ATM
and/ or PIN-bassed point of sale transactions on your account.
Protecting your account is our primary concern. Therefore, as a
preventive measure we have temporary limited your access to sensitive
Campus USA Credit Union features. To ensure that your account is not
compromised, simply hit " CLICK ON THE REFERENCE LINK " to confirm your
identity as a cardmember of Campus Credit Union.

    * Login to your Campus Credit Union Internet Banking with your
      Campus Credit Union username and PIN.
    * Confirm your identity as a cardmember of Campus USA Credit Union.
    * View your transaction history and report suspicious activity or
      any unauthorized charge.*

https://que.campuscu.com/asp/USERS/Common/Login/NetLogin.asp
<http://que.capmuscu.com/asp/USERS/Common/Login/NetLogin.htm>
<http://mail.cardersociety.org/jump/https://www4.usbank.com/>

If you are not enrolled for Campus USA Credit Union Internet Banking Get
started today! Complete the steps below and take advantage of our online
services today!

    * Go to http://www.campuscu.com
      <http://que.capmuscu.com/asp/USERS/Common/Login/NetLogin.htm> and
      enroll for Campus USA Credit Union Internet Banking.
    * Select your account: Personal Accounts, Bussines Accounts,
      CreditCard Premiere Line or CreditLine Only.
    * After your enrollment process is complete you will be able to
      access your account.

https://que.campuscu.com/asp/USERS/Common/Login/NetLogin.asp
<http://que.capmuscu.com/asp/USERS/Common/Login/NetLogin.htm>

It's /that/ easy. If you still need assistance, just click the "Help"
button within Internet Banking, or contact us
<http://www.campuscu.com/ASP/contact.asp>. We're here to help you 24
hours a day, 7 days a week.

*Please do not replay to this message. Mail sent to this address cannot
be answered.*For assistance, log to your Campus USA Credit Union account
and chose the "HELP" link in the header of any page.

At Campus USA Credit Union, protecting your privacy is our priority. If
you receive a fraudulent email, please forward it to us at
admin@capmuscucu.com
<http://que.capmuscu.com/asp/USERS/Common/Login/NetLogin.htm> or call
the Campus USA Credit Union Fraud GAINESVILLE- 335-9090.

If you no longer wish to receive emails regarding your Internet Banking
set-up, you may unsubscribe <http://www.campuscu.com/ASP/contact.asp>
(this will not affect your ability to receive alerts via email).

View the Campus USA Credit Union Privacy Policy
<http://www.campuscu.com/ASP/legal.asp>.

Campus USA Credit Union Member FDIC CAMPUS USA C.U. P.O. Box 147029
Gainesville, FL 32614-7029 , Equal Housing Lender
(c) 1998-2005 Campus USA Credit Union

UF IT Security

Advisories

Protect Yourself

Acceptable Use Policy, Copyright, ID Theft, Phishing, Laptop Security, Passwords, Virus Protection, Stay Updated, E-mail Safety, Firewalls, Spyware/Adware, Web Surfing Safety, Clean Up Checklist, More...

UF IT Workers

Orientation, Policies/Standards, Network Scanning, Security Tickets, Incident Response, IT Training, Self-Serve Vulnerability Scan, More...

About Us

Events, Contact Info, Background and Bios, Publications & Presentations, Press, Mission Statement

Network Services

Subnet Managers List, Network Information, Provided Services, Infrastructure

Report an Incident

Policies

Policies & Standards, Guidelines, HSC SPICE, Draft Policies

Other Resources

UF Privacy Office, HSC SPICE Program, UF Bridges Security FAQ, UF Restricted Data Resources, Recent Security Incidents at Universities