A strategy for handling of Phishing attacks against universities

Phishing attacks against universities have become a serious problem over the past three years. Criminals collect university user accounts to send spam/malware/phishing mail and to host phishing web pages.

Universities are an ideal target for phishers because they provide a large pool of diverse users and because universities are unlikely to blacklist other universities.

At the Swiss Federal Institute of Technology (ETH Zürich), our Mail, Security and Helpdesk groups have collaborated to develop a multi-pronged strategy to handle phishing attacks. Although we are not able to entirely block the phishing messages, we can limit their impact.


