Information Security
Security News
Security News – Understanding and responding to Log4Shell and other Log4j-Related vulnerabilities.
Information Security Training
Read our FAQ for more information about Core Information Security Awareness training.
How can we help you?
- Report a possible phishing attempt
- I need to complete Security Awareness Training
- I need to reset or recertify my CNetID or password.
- I want to know how to use two-factor authentication.
- I need an SSL, code signing, or some other kind of security certificate.
- Report a possible compromise or other security incident
- I have a question about security for my application or have my application reviewed.
- My account was locked for spamming or due to some other security issue.
- I need access to phone records, emails, or other data for an investigation or personnel matter.
- I’m traveling and received an email asking that I contact the security team.
- My computer or phone was blocked from the network due to a virus detection.
- I want to send the security team a report about a security vulnerability or some other issue I discovered.
- A website I tried to visit is blocked and erroneously listed as suspicious. What do I do?
IT Policies
Refer to the University’s official IT policies regarding data security and use of copyrighted material.
Training and User Guides
Complete security training and get user guides for helpful security tips and advice.
Phishing Alerts
Listed below are the latest phishing scams that have been acted upon by Information Security. Think you’ve received a phishing email? Don’t click it, report it.
Email Scam (June 22, 2022): Fw EAP Benefits Program
From: “"Kapsner, Elizabeth" <ekapsner@nwacc.edu> Date: Wed, 22 June 2022, 03:46:18 +0000 Subject: Fw EAP Benefits Program
Email Scam (May 31, 2022): Document shared with you: ADMIN EVALUATION FILE
From: "Stacy Schwab (via Google Docs)" <drive-shares-dm-noreply@google.com> Date: Tue, 31 May 2022 17:37:20 +0000 Subject: Document shared with you: "ADMIN EVALUATION FILE"
Email Scam (March 8, 2022): “MEMO FROM HR”
From: "Mchenry, Kyle" <Kyle.Mchenry@fortbendisd.com> Date: Tue, 8 Mar 2022 17:22:52 +0000 Subject: MEMO FROM HR Good Day, You have a message from the Human Resources Department Click here<hxxps://isgrioja[.]com/MjIxSTNiOGo1MzJKMDM=> to view your message...
Security News
Check here for the latest security alerts that may affect you.
Cybersecurity First – Oct 25, 2021
Cybersecurity is a Team Sport Cybersecurity is a shared responsibility, and the University of Chicago’s security efforts will only be successful when all members of the campus community understand the risks and take steps to avoid them. We offer the following tips to...
Cybersecurity Career Awareness Week
Cybersecurity is a dynamic and rapidly growing field, with new threats and challenges emerging each day. And with that, there is a huge push being undertaken by both business and education sectors to attract individuals toward a degree and career in cyber. Whether...
Protecting Yourself Against Ransomware Attacks
In week 1 of Cybersecurity Awareness Month, we focused on educating you on the different types of phishing attacks we have seen and that many have reported receiving in the UChicago community. The most important element in a successful phishing attack is the human...
5 Ways to Outsmart a Social Engineer
“Social engineering” is a newer term for an age-old pursuit: tricking people. Whether you use the modern-day terminology or opt for longer-standing classifications (like conning, hustling, and swindling), the result is the same. Scammers aren’t afraid to tell lies—...
Ransomware Attacks
Ransomware attacks are one of the most serious cybersecurity threats we face at the University of Chicago. Ransomware is a type of malicious software that steals user data, disables the user system, and then demands payment from the victim in order to reenable system...
3 Steps to Fight Phishing
Chances are good that at some point you’ve received a suspicious email urging you to click on a link or open an attachment. This email was most likely an example of the cybercrime known as phishing. Phishing is when cybercriminals send malicious emails designed to...
3 Tips to Managing Passwords and PINs to Avoid Account Compromise
We have so much to remember every day. Add to that the dozens (or more) passwords and PINs we must remember in order to log in to work and personal accounts, and it’s easy to feel overwhelmed. And when we’re overwhelmed, it’s easy...
3 Facts About the Internet of Things (IoT) and Guide to Best Practices
It’s likely you own one or more items that are part of the Internet of Things (IoT). This collective term is used to describe a growing number of consumer, medical, and business items that are used to sense, control, and communicate data and activities. The IoT has...
3 Wi-Fi Habits to Adopt Today
Studies have shown that most mobile device users — even those who are security-savvy — tend to throw caution to the wind when it comes to connecting to open-access, public Wi-Fi networks. Public networks are displayed in the list of Wi-Fi networks without a lock icon....
Beware Coronavirus (COVID-19) Cyber Scams
We would like to warn everyone to remain vigilant for scams related to coronavirus 2019 (COVID-19). Cyber criminals may send phishing emails with malicious attachments or links to fraudulent websites to trick victims into revealing sensitive information or donating to...