Tips:
- Report suspected compromises as soon as possible. Early reporting can significantly reduce the impact.
- Do not continue using a computer that you believe may be compromised for banking, email, university work, or changing passwords.
- If possible, use a different trusted device to change passwords or contact the Service Desk.
- Do not delete suspicious messages, files, applications, or browser extensions before contacting IT. They may help determine what occurred.
- Never approve an MFA request you did not initiate.
- When in doubt, contact the Service Desk. You do not need to determine whether something is actually malicious before reporting it.
FAQs:
How do I know if my USD account may be compromised?
Possible signs include:
- MFA notifications or approval requests you did not initiate.
- Password reset messages you did not request.
- Emails appearing in your Sent, Deleted, or Draft folders that you did not create.
- Friends, coworkers, or classmates receiving unusual messages from your account.
- Unexpected changes to your email forwarding rules, inbox rules, or account settings.
- Sign-in notifications from locations or devices you do not recognize.
- Your password suddenly no longer works.
- Unexpected changes to university records, files, Microsoft 365, OneDrive, Teams, or other services.
What should I do if I think my USD account has been compromised?
- Contact the Service Desk immediately.
- If possible, use a different trusted device to change your USD password.
- Do not approve any unexpected MFA notifications.
- Tell IT if you entered your password into a suspicious website or approved an MFA request.
- Tell IT if the same password was used for any other account. You should also change those passwords.
- Review other important accounts, particularly financial, banking, personal email, and social media accounts, for unexpected activity.
What should I do if I think my computer is compromised?
If you notice suspicious activity, malware warnings, unknown programs, unexpected browser behavior, or believe you installed something unsafe:
- Stop using the computer for sensitive activities.
- If the activity appears serious or is actively occurring, disconnect the computer from Wi-Fi or the wired network, but leave the computer powered on unless instructed otherwise by IT.
- Contact the Service Desk from another device if possible.
- Do not attempt to remove suspicious programs, clear browser history, delete files, or reinstall the computer unless instructed by IT.
- Be prepared to explain what happened and approximately when it occurred.
Can phishing compromise my account or computer?
Yes. Phishing messages commonly attempt to convince you to:
- Enter your username and password into a fake login page.
- Approve an MFA request.
- Open a malicious attachment.
- Download software.
- Scan a QR code that leads to a malicious website.
- Call a fake support number.
- Give someone remote access to your computer.
Phishing may arrive through email, text messages, social media, Teams, messaging applications, or even phone calls.
I clicked a phishing link but did not enter my password. Do I still need to report it?
If you only opened a webpage and did not enter information, download anything, approve an MFA request, or allow browser notifications, the risk may be lower. However, if anything unusual occurred or you are unsure what happened, contact USD Information Technology.
If you entered your password, downloaded or opened a file, approved an MFA request, installed software, or granted permissions to an application, report it immediately.
I accidentally approved an MFA request. What should I do?
Contact the Service Desk immediately and explain that you approved an MFA request you did not initiate. An attacker who already has your password may use an MFA approval to complete a login to your account.
Never approve an MFA request simply to make repeated notifications stop.
Can downloaded software compromise my computer?
Yes. Software downloaded outside of trusted sources may contain malware even when the program appears to work normally. Be especially cautious with:
- Free versions of normally paid software.
- Cracked or pirated software.
- Game cheats, modifications, key generators, and activation tools.
- Video downloaders and media conversion utilities.
- Unofficial PDF editors or converters.
- Free VPN or proxy software.
- Cryptocurrency-related utilities.
- Programs advertised through pop-ups or questionable websites.
If software requires you to disable antivirus protection, ignore a security warning, or run an unusual command before installation, stop and contact the Service Desk if the device is used to access USD resources.
Why are illegal or pirated downloads a security concern?
Pirated movies, games, software, books, and other unauthorized downloads are frequently distributed through websites and file-sharing networks where content is not verified. Downloads may contain password-stealing malware, remote-access software, cryptocurrency miners, or other malicious programs.
In addition to copyright and legal concerns, downloading pirated content can put your USD account, university information, and personal information at risk.
Are file-sharing or video-sharing applications dangerous?
Some peer-to-peer (P2P), torrent, file-sharing, and video-sharing applications may expose your computer to untrusted users or download content from unknown sources. Some applications may also continue running in the background and allow files, network bandwidth, or other computer resources to be shared without the user fully understanding what is occurring.
If you installed a file-sharing application and notice unusual computer or network activity, contact the Service Desk.
Can a browser extension compromise my account?
Yes. Browser extensions can have extensive access to what you view and enter into websites. Depending on the permissions granted, an extension may be able to read webpage contents, modify websites, observe browsing activity, or access information entered into web pages.
Be particularly cautious of extensions advertising:
- Free AI assistants or productivity tools.
- Free PDF editing or conversion.
- Free video downloading.
- Coupon or shopping assistance.
- Free VPN or proxy services.
- Free access to paid services.
- Browser search enhancements.
- Cryptocurrency or investment tools.
Only install browser extensions you actually need, obtain them from reputable sources, and review the permissions they request.
What are residential proxy applications and why are they a concern?
A residential proxy service allows other people or organizations to send internet traffic through another person's internet connection. Some applications offer money, free services, VPN access, downloads, or other benefits in exchange for allowing the application to use your internet connection.
This can result in unknown third-party activity appearing to originate from your device or network. It may also introduce security, privacy, performance, and legal risks.
Do not install software that offers compensation, free services, or other benefits in exchange for sharing your internet connection or bandwidth on a computer used to access USD resources.
What about devices that provide free movies, sports, or streaming services?
Use caution with streaming boxes, modified streaming devices, USB devices, applications, or other hardware advertised as providing free access to normally paid television, sports, movies, or subscription services.
These devices or applications may:
- Use unauthorized streaming services.
- Contain malicious or modified software.
- Connect to unknown servers or networks.
- Act as a proxy for other users.
- Collect account credentials or personal information.
- Expose other devices on your home network.
A product functioning as advertised does not necessarily mean it is safe.
Can a free VPN or proxy service be dangerous?
Yes. VPN and proxy providers are in a position to observe or redirect network traffic. Some free services make money through advertising, collection of browsing information, installation of additional software, or sharing of a user's network connection.
Do not assume a service is trustworthy simply because it is available through a browser extension or application store.
Someone claiming to be technical support wants remote access to my computer. What should I do?
Do not provide remote access unless you independently verified that you are working with legitimate USD Information Technology personnel or another support provider you intentionally contacted.
Attackers commonly impersonate Microsoft, Apple, banks, antivirus companies, government agencies, and university IT departments and then ask users to install remote-access software.
If you already gave an unknown person remote access to your computer, disconnect the device from the network and contact the Service Desk immediately.
Should I remove malware or suspicious applications myself?
Not necessarily. Removing or modifying software can make an investigation more difficult and does not guarantee that all malicious software has been removed.
For university-owned devices, contact the Service Desk before attempting to remove suspected malware or reload the computer.
What information should I provide when reporting an incident?
Provide as much information as you can, including:
- Your name and USD username.
- The computer, phone, or other device involved.
- Approximately when the activity occurred.
- What you clicked, downloaded, installed, or opened.
- Whether you entered your password.
- Whether you approved an MFA request.
- Whether you installed an application, browser extension, VPN, proxy, or remote-access software.
- Any error messages, security alerts, screen shots, emails, or websites involved.
- Whether financial, student, research, health, or other sensitive university information may have been accessible from the device or account.
You do not need to investigate the problem yourself before reporting it. Providing a straightforward description of what occurred helps IT respond more quickly.
Will I get in trouble for reporting that I clicked something or installed something unsafe?
The most important action is to report the issue quickly. Delaying a report can allow an attacker additional time to access email, files, accounts, or other university resources.
Even if the compromise resulted from a mistake, unexpected download, unsafe application, or phishing message, promptly telling IT exactly what happened provides the best opportunity to contain the incident.
Can my personal computer affect my USD account?
Yes. A compromised personal computer, phone, or tablet can expose USD credentials and information when it is used to access university email, Microsoft 365, university applications, or other USD services.
If you believe a personally owned device used for USD access is compromised, contact USD Information Technology and avoid using that device to access university resources until it has been secured.
How can I reduce the chance of this happening again?
- Do not reuse your USD password on other websites.
- Never approve an MFA request you did not initiate.
- Keep your operating system, browser, and applications updated.
- Only install software and browser extensions that you need and trust.
- Avoid pirated software and unauthorized media downloads.
- Avoid applications that promise free services in exchange for bandwidth, network access, or installing additional software.
- Be suspicious of unexpected links, QR codes, attachments, and login requests.
- Do not provide remote access to someone who unexpectedly contacts you.
- Contact USD Information Technology whenever you are uncertain whether something is legitimate.