As technology advances – so do the scam artists.
That is why the University System of New Hampshire (USNH) Enterprise and Technology Services (ET&S) is changing how phishing attempts are prevented in email inboxes.
Joe Gray, director of cybersecurity operations and identity access management, said it will now be switching to Abnormal Email Security, a partner of Microsoft, officially on April 16.
As of Tuesday, April 2, Gray said Abnormal has found 528,000 phishing attempts – a type of scam that attempts to compromise information – have been made across the USNH community.
The ET&S team noticed, that while Microsoft is not bad, it has allowed a significant amount of phishing attempts to come through.
The current system directly through Microsoft sends emails into “quarantine.” Gray said this was Microsoft’s way of protecting users from harmful emails. When an email is sent into quarantine, depending on how harmful the email is, the recipient or an analyst can release the email back into the user’s inbox.
Since January, Gray said there have been three major successful phishing campaigns – real phishing attempts. One of which resulted in 80 compromised accounts across students, faculty and staff. Additionally, during that same campaign, two employees fell victim and the rest were students, Gray noted.
“We [had to] secure accounts and make people reset their passwords and everything,” Gray said. “This is a problem.”
To help identify phishing attempts ET&S occasionally sends simulation phishing emails to its students faculty and staff. If someone reports the email as phishing, a message will show congratulating the student on identifying the phishing attempt.
The emails are a part of an “Internal anti-phishing education campaign,” according to one of the emails.
“This is just a way of training people to recognize what phishing looks like,” Gray said.
One such email was sent on March 27. The email detailed a “Part-time Administrative Assistant” on-campus job opportunity. The email was sent by the fake “Dr. Steve Jones” with the email address “Steve.Jones@usnh.eud.org”
The email stated the salary and asked the recipient to reply to the message with their email, personal phone number and availability.
While Gray does not have the full data set from this latest simulation, the September 2023 simulation resulted in 1,571 students reporting it as phishing out of the 29,128 emails delivered. As for USNH employees, 1,341 reported it as phishing out of the 8,005 emails sent out.
However, 6,104 students clicked the link in the email, furthermore, 2,708 students supplied their credentials. Additionally, 625 employees clicked on the link and 302 submitted their credentials.
At Keene State College, Campus Safety Officer, Ian Matheson, said commonly students will receive email scams sent to their KSC email address. Another popular scam students may receive is a text message from someone pretending to be from UPS or USPS.
In regards to the emails sent to students, it can come in different ways. One way Matheson said, is an employment scam.
Typically, the email will state there is a job or an internship opportunity. The scammer will write in the email that the opportunity offers X amount of money and click a link to apply.
“Our students are very eagle-eyed and they send it to us,” Matheson said.
One of those scam emails received by The Equinox on March 12, stated in the subject “Campus Job opportunity.” The email contained only a PDF and no actual email body.
The Equinox did not open or download the PDF to protect itself from any potentially harmful malware.
In terms of text message scams, Matheson said the UPS or USPS scam will state a person’s package has been lost and to click the link in the message. Matheson said if someone clicks the link, it can download spyware onto the user’s phone and gather personal information and data.
One way to protect yourself from these types of scams is to not click on suspicious links.
Matheson said if you are not expecting an email or a text from someone and it’s from someone you do not know the likelihood of it being a scam is there. On the note of the UPS or USPS scam, if you are not expecting a package, it is a scam.
“If it seems off … It’s probably off,” Matheson said.
Another way to protect your information is to be careful about what you post on social media. Scam artists can gather your information that way, especially anything related to security questions, like your mother’s maiden name or what street you grew up on.
A type of scam Matheson said the Campus Safety Instagram account has been receiving lately pertains to a scammer being locked out of their account and trying to get back in by asking for your email as a recovery method.
Matheson said this is just a way for the scammer to try and get into your account.
Other ways USNH looks to protect its community is through the Microsoft Authenticator App. Previously, it just asked for a number, now it will tell you the location the sign-on is coming from, Gray said.
“Now you can say, ‘Hey, I’m not in Oklahoma or I’m not in Florida,’ ” he said.
Across USNH, around $20,000 was lost to phishing attempts in 2022. Gray said one such incident, a parent lost around $1,000.
Annually, the Federal Trade Commission (FTC) releases the Consumer Sentinel Network Data Book, which details scam data throughout the year.
In 2023, there were 2.9 million reports of fraud and 5.4 million reports in general, according to the report.
Of young people aged 20 to 29, 44% reported fraud, with only 25% aged 70 to 79.
However, for people above the age of 70, the median loss of money was much higher.
Compared to 2022, the FTC reported adults ages 18 to 59 were 34% more likely to report losing money to fraud than adults 60 and over.
Additionally, young adults commonly fall victim to online shopping scams through social media. The FTC also reported that younger adults were four times more likely to fall victim to investment scams than their older counterparts.
Tim Bruns can be contacted at










