Students’ emails hacked in multiple phishing events

Example of punchbowl invitation phishing email – Index Staff

A notification slides onto the screen. “You have a New Document from The Haverford School,” it reads. The sender’s address belongs to someone you trust. 

Click.

A large, official-looking Punchbowl invitation and a green “open invitation” button sit in the middle of the screen. The button opens a pop-up with a login page. A username and password are entered. The Enter key is pressed. Nothing happens. 

Hours later, emails begin pouring out, this time from a new email address, but still containing the official-looking letter and button. None of them were sent intentionally. Instead, they were sent as a result of one of the most common cybersecurity attacks: phishing.

“We have two layers of filtering: the workspace education layer, which is Google, and filtering at our firewall level.”

MR. Paul Blackwood

“ A phishing email is a spam email with a link, and when you choose that link, [it] launches some kind of background script that grabs your contact list and then uses that contact list of names [and] email addresses to continue sending itself to other folks,” Director of Information Technology Mr. Paul Blackwood said. “So each time someone clicks on that link, it then repeats the cycle.”

Mr. Blackwood said K–12 institutions such as Haverford can be particularly vulnerable to these attacks.

“ K to 12 schools are being targeted … because students, employees, faculty, and staff are not as vigilant because we expect emails to be coming from many different sources, so we’re not as vigilant with how we examine the emails,” Mr. Blackwood said. 

To combat phishing attempts, Haverford uses several security measures.

“ We enact multiple layers of security,” Mr. Blackwood said. “One is educating people. We have two layers of filtering: the workspace education layer, which is Google, and filtering at our firewall level.”

Haverford’s email system also uses authentication standards to help determine whether incoming messages are legitimate.

“ In an email system, we have three boxes that need to be checked,” Mr. Blackwood said. “They’re called DKIM, SPF, and DMARC. They’re all industry standards for what a legitimate email should possess in what we call an email signature.”

However, these methods are not foolproof. 

“ Some emails do get through because, as the nature of how we identify these emails evolves, so do the spam and the spammers,” Mr. Blackwood said.

Especially in the past year, these attacks have occurred multiple times. One of the initial Haverford students to have fallen victim to such an attack is a familiar face to many.

“It was the first day of spring break, and I clicked on an email from a friend’s mom, and it said [I was] invited to this party,” Sixth Former Raymond Kresge said. “ It prompted me for my email and my password, and then once I put it in, it didn’t go anywhere. Three hours later, I was driving … and I got all these notifications from Gmail from all these teachers that have automated email responses, and I kept freaking out.”

“People fall victim to this all the time.”

Ray Kresge ’27

Although the problem was later resolved, Kresge’s experience demonstrates how a phishing email sent through a familiar account can lower a recipient’s guard.

“ I just took everything that I saw on my school Gmail as secure,” Kresge said. “ Every email that I get, I’m not going on and checking the sender.  I remember I got [invited] days before [for] the Cum Laude breakfast … It was that same style, and since I already knew that style was reputable,  I was like, ‘Oh, this is from this person.’”

Kresge said students can take simple steps to avoid making the same mistake.

“ People fall victim to this all the time,” Kresge said. “Just stop and think for a minute, especially if you’re getting [an] invitation email, and looking at those URLs are just two simple ways to [stay safe].”