ALERTS

STUDENTS INTERN type or similar Scam (Mar 3 9:30 am)

Members of the university community, especially students, have been targeted by phishing attacks in which the attackers impersonate a UH Professor. The attackers are using names of actual UH Professors in these phishing emails, along with a phone number to text. The attacker will contact the victim, often under the pretext of being related to an employment opportunity, and then engages with and persuades the victim to send out emails from the victim's hawaii.edu account. The attacker provides the text of the message to send, as well as a list of email addresses. Once the victim has sent out the emails, the attacker will provide the victim with a fake check as "payment".
 
Although in this scam the attacker does not gain access to the victim's account, the victim is affected in the following ways:

  • Due to the amount of emails sent out, the victim's hawaii.edu account could be disabled by ITS or locked by Google.
  • Since the emails are coming from a hawaii.edu account, it may lull others into believing the emails are legitimate.
  • Sending phishing emails from a hawaii.edu account could damage the reputation of the hawaii.edu domain and impact email deliverability.
  • Cashing or depositing a fraudulent check can have consequences for the financial institution the victim banks at, and can lead to their account being frozen while further investigation is conducted by the authorities - even if they did not realize the check was fake.


If you receive a message that appears to be from a UH Professor or other UH person that provides a phone number as a contact, please exercise caution when responding.
  • Do not give out any personal information.
  • Do not respond to unknown individuals from your personal mobile phone number.
  • If the person asks you to send out email messages on their behalf, stop engaging with the person immediately.


One example of this type of scam email may be viewed in this alert:  https://www.hawaii.edu/its/alerts/?t=3&id=10437
 
Please note that sending out unsolicited bulk email messages is prohibited by EP 2.210 (page 8). You should never send out unsolicited bulk email messages either for yourself or at the request of someone else.
 
In general, be wary of unsolicited job offerings not offered through official UH channels. UH positions are posted at the Student Employment and Cooperative Education (SECE) website for student employee positions or at OHR’s Work at UH (NEOGOV) website for Faculty, Staff, Grad Assistantships, etc.
 
For more information about phishing and tips to protect yourself from phishing attempts, please visit UH Infosec’s website on phishing.