Power Up Your Protection - Level 1: Account Takeover

Power Up Your Protection - Level 1: Account Takeover

Quick Overview
  • Covers phishing in chat apps, business email compromise, and text message scams
  • Opens Tuesday, Oct. 6 in ZenGuide; start it from your Level 1 email from IT Security
  • Takes about 15 minutes
  • Optional; all levels should be completed by Friday, Oct. 30

This week is all about account takeover: the tricks attackers use to steal your login and use it against you, your coworkers, and SFA.

In This Level

  • Threat Overview: Phishing in Messaging Apps (video)
  • Email Attack Methods: Business Email Compromise (video)
  • Social Engineering: Smishing Attacks (video)
  • Check, Please! (game)

Know the Signs

  • Urgent requests for gift cards, wire transfers, or changes to direct deposit or payment details
  • Texts about package deliveries, unpaid tolls, account problems, or prizes
  • Chat messages from unknown accounts asking you to click a link, open a file, or move to another app
  • Any request for your password, a Duo passcode, or a code sent to your phone

Protect Yourself

  • Verify unusual requests by calling the person at a number you already know, not one in the message
  • Deny any Duo prompt you did not start, then report it
  • Don’t reply to or click suspicious messages. Report suspicious emails with the Report Phish button in Outlook.
!
Important
Never share your password or a Duo passcode with anyone, including someone who says they are from ITS.

This Week’s Challenge

  1. Turn on MFA for one personal account that doesn’t have it yet, like your personal email or bank.
  2. Verify a request: confirm the next unusual request for money, data, or access by phone or in person.
  3. Report a scam: find one suspicious email or text and report it.
i
Tip
Attackers want you to act fast. Slow down and verify.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. Report suspicious emails with the Report Phish button in Outlook (How to Report a Phishing Email).