Stay Current with IT Security Notices
The DoIT Security Group regularly posts alerts and insights regarding active cyber threats, phishing scams, and system security updates. Follow our myUMBC group to receive instant notifications and security bulletins directly in your email inbox and myUMBC feed.
Cybersecurity Alerts
Gift Card Scams Are Targeting UMBC Staff
If it seems weird, it is. Don't do it.
For several years, UMBC's Division of Information Technology has received reports of gift card scams. Recently, some of these scams have been sent as text messages to personal phones, falsely...
Posted: July 31, 2024, 9:02 PM
Concerning Job Scams
Holidays and long weekends attempt to catch users off guard
Over the weekend the Division of Information Technology has gotten reports of several job scams sent to users by email. These scams promise good pay for minimal effort, usually at home on your own...
Posted: June 20, 2023, 4:33 PM
Event ticket sales paused due to vendor security concerns
UMBC has been informed that a third-party vendor for campus event ticketing, AudienceView (also known as University Tickets), recently experienced a payment card data security breach with its...
Posted: February 28, 2023, 3:59 PM
Two Unusual Phishing Campaigns
Scammers get creative
Recently the Division of Information Technology (DoIT) received notification of two phishing campaigns at other universities. While neither of these has been reported at UMBC, we are posting this...
Posted: January 6, 2023, 4:44 PM
Protecting your online account over Winter Break
As we prepare for the winter break, we commonly see a surge in malicious activity toward user accounts. Users receive emails warning about unpaid invoices, expired passwords, or full inboxes....
Posted: December 22, 2022, 1:44 PM
Account Data Breach: START
Russian streaming service impacts over 7 million accounts
In August 2022, news broke of an attack against the Russian streaming service "START". The incident led to the exposure of 44 million records containing 7.4 million unique email addresses. The...
Posted: November 4, 2022, 3:08 PM
Account Data Breach: TAP Air Portugal
Portugal's national airline victim of ransomware attack
In August 2022, the Portuguese airline TAP Air Portugal was the target of a ransomware attack perpetrated by the Ragnar Locker gang who later leaked the compromised data via a public dark web...
Posted: October 28, 2022, 3:07 PM
Account Data Breach: Twitter
Hackers list database of 5.4 million records for sale
In January 2022, a vulnerability in Twitter's platform allowed an attacker to build a database of email addresses and phone numbers of millions of users of the social platform. In a disclosure...
Posted: October 19, 2022, 3:23 PM
Account Data Breach: SitePoint
Shared data has already been used in attacks
In June 2020, the web development site SitePoint suffered a data breach that exposed over one million customer records. Impacted data included email and IP addresses, names, usernames, bios and...
Posted: October 18, 2022, 4:05 PM
Account Data Breach: ShitExpress
In August 2022, the online feces delivery service ShitExpress suffered a data breach that exposed 24,000 unique email addresses. The addresses spanned invoices, gift cards, promotions and PayPal...
Posted: October 18, 2022, 3:57 PM
- Go to page 1
- Go to page 2
- Go to page 3
- Go to page 4
- Go to page 5
- Go to page 6
- …
- Go to page 29