{"id":1040,"date":"2017-05-03T15:01:05","date_gmt":"2017-05-03T20:01:05","guid":{"rendered":"http:\/\/sites.augsburg.edu\/it\/?p=1040"},"modified":"2025-08-11T09:19:27","modified_gmt":"2025-08-11T14:19:27","slug":"sharing-google-documents-or-another-phishing-attack","status":"publish","type":"post","link":"https:\/\/sites.augsburg.edu\/it\/2017\/05\/03\/sharing-google-documents-or-another-phishing-attack\/","title":{"rendered":"Sharing Google documents or another phishing attack?"},"content":{"rendered":"<h2>What happened?<\/h2>\n<p>The afternoon of May 3 saw a widespread phishing attack across the internet. \u00a0The phishing attack is an email that looks like a Google document sharing request as shown below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1041\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM.png\" alt=\"\" width=\"535\" height=\"203\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM.png 535w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM-300x114.png 300w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM-100x38.png 100w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM-150x57.png 150w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM-200x76.png 200w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.37.54-PM-450x171.png 450w\" sizes=\"auto, (max-width: 535px) 85vw, 535px\" \/><\/p>\n<p>It is a convincing phish but note the odd To: address. \u00a0That should be a warning sign that something is off. \u00a0In some cases people recognized the name of the person but perhaps it was spelled slightly wrong. \u00a0That&#8217;s another warning sign.<\/p>\n<p>The link, which you should\u00a0<strong>not<\/strong> click on, takes you to a page that appears to request access to your Google account. \u00a0Real Google docs do not need this access. \u00a0Once you grant access they will try to send more messages\u00a0<strong>using your account<\/strong> to your contact list.<\/p>\n<h2>What can I do?<\/h2>\n<p><strong>First<\/strong>, if you clicked the link you should change your password on <a href=\"http:\/\/sites.augsburg.edu\">Inside Augsburg<\/a>. \u00a0This is true for any phishing email that has fooled you into clicking on a link.<\/p>\n<p><strong>Second<\/strong>, and more importantly this time, is you need to review all connected Applications and Websites connected to your Google account. \u00a0The phish has tricked you into giving their application access to your Google account. \u00a0You do not want that.<\/p>\n<p>This is done in three quick steps.<\/p>\n<ol>\n<li>Visit <a href=\"https:\/\/accounts.google.com\">https:\/\/accounts.google.com<\/a><\/li>\n<li>Under\u00a0<strong>Sign-in &amp; Security<\/strong> pick\u00a0<strong><a href=\"https:\/\/myaccount.google.com\/security#connectedapps\">Connected apps &amp; sites<\/a><\/strong><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1042\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM.png\" alt=\"\" width=\"415\" height=\"336\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM.png 415w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM-300x243.png 300w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM-100x81.png 100w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM-150x121.png 150w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.49.13-PM-200x162.png 200w\" sizes=\"auto, (max-width: 415px) 85vw, 415px\" \/><\/li>\n<li>Click\u00a0<strong>MANAGE APPS<\/strong> and review and <strong>remove<\/strong> any sites or apps that you do not recognize. \u00a0This phish\u00a0shows up as &#8220;<em>Google Docs<\/em>&#8221; which is very tricky. \u00a0If you see that listed, remove it.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1043\" src=\"http:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM.png\" alt=\"\" width=\"1078\" height=\"405\" srcset=\"https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM.png 1078w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-300x113.png 300w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-768x289.png 768w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-1024x385.png 1024w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-100x38.png 100w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-150x56.png 150w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-200x75.png 200w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-450x169.png 450w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-600x225.png 600w, https:\/\/sites.augsburg.edu\/it\/files\/2017\/05\/Screen-Shot-2017-05-03-at-2.50.45-PM-900x338.png 900w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h2>How can I learn more about information security?<\/h2>\n<p>We have a broad information security self-paced course in moodle that anyone at Augsburg can complete to improve their information security awareness skills. \u00a0The course has about 35 minutes of short videos (closed captioned, no sound required). \u00a0You can find it in moodle community at the following address <a href=\"https:\/\/moodle.augsburg.edu\/moodlecommunity\/course\/view.php?id=946\">https:\/\/moodle.augsburg.edu\/moodlecommunity\/course\/view.php?id=946<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What happened? The afternoon of May 3 saw a widespread phishing attack across the internet. \u00a0The phishing attack is an email that looks like a Google document sharing request as shown below. It is a convincing phish but note the odd To: address. \u00a0That should be a warning sign that something is off. \u00a0In some &hellip; <a href=\"https:\/\/sites.augsburg.edu\/it\/2017\/05\/03\/sharing-google-documents-or-another-phishing-attack\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Sharing Google documents or another phishing attack?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":37,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,3],"tags":[],"class_list":["post-1040","post","type-post","status-publish","format-standard","hentry","category-phishing","category-security"],"_links":{"self":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/comments?post=1040"}],"version-history":[{"count":5,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1040\/revisions"}],"predecessor-version":[{"id":1048,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/posts\/1040\/revisions\/1048"}],"wp:attachment":[{"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/media?parent=1040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/categories?post=1040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.augsburg.edu\/it\/wp-json\/wp\/v2\/tags?post=1040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}