“Appointment” as professor at Harvard was an elaborate phishing attack
ndtv.com
ndtv.com
Victim blaming and questioning how she could believe that she’s qualified for some position is the wrong thing to talk about, and is also disgusting in certain ways.
What would be better, at least in a tech focused community, is to find out more details on how this happened and where the gaps (that are obvious in hindsight) are. I wish someone like Brian Krebs (of Krebs on Security) could get more information on this and do a detailed write up. That would be more insightful and useful to everyone than rants about the victim.
The reality is that we all do things when we're distracted and not really paying attention. Or we get caught up in the excitement of something and we don't stand back and ask ourselves whether it really makes sense. And anyone who thinks otherwise is just arrogant and misguided.
Edit: https://twitter.com/ruchirsharma_1/status/135006726628985651...
It seems that this may not even have been a phishing attempt.
Also, one would expect any open position at a US university to be advertised, most likely in The Chronicle of Higher Education. This is something perhaps only someone who's got a little familiarity with the academic job market may know, so, I suppose one could be forgiven for not knowing it, but I would assume that one would at least google for open positions at Harvard to find out if it really exists.
That said, naïve or not, I also don't think victim blaming is a productive thing to do here. All it does is discourage people from speaking out about their experiences, which means we can't learn from them. It may also discourage people from seeking help when they think they might be getting phished.
Example: https://pbs.twimg.com/media/ErxnAc5XEAEkro3?format=jpg&name=...
It makes no sense for her to fake all of this for some "clout" as some on twitter suggested - she does not need it. Unfortunately there is a lot of cynicism for anything media (and in turn politics) related in India and people love to speculate.
It's possible there's an innocent explanation but Occam's Razor does suggest she just made up her Associate Professor at Harvard title and, when called out for it, concocted a story about it really being Harvard Extension School and phishing. Which was vaguely plausible so long as you don't think too deeply about it and ignore that, if this were the case, the initial Twitter post was deceptive.
Again, this is a lot of esoterica about the academic job market that not many people outside of those circles is going to know, so I don't blame anyone for not knowing it.
ADDED: And, yes, there seem to be different claims on twitter than what is stated in this post.
I am not sure how much more clear I can be with you. Nidhi Razdan claimed on Twitter that she was joining the Harvard Faculty of Arts and Sciences as an Associate Professor. The Harvard Extension School has absolutely nothing to do with any of this. Here is the original tweet:
This is not something someone without a research background would know.
What an "associate professor" is isn't common knowledge, even for a journalist. It both means something different in Commonwealth countries and the definition of "associate" is "entry level" which doesn't fit either version of an associate professor.
https://www.investopedia.com/articles/markets/081315/look-co...
https://www.forbes.com/sites/augustinefou/2021/01/02/when-bi... :When Big Brands Stopped Spending On Digital Ads, Nothing Happened. Why?
In case it matters, a number of these don't advertise, at least not in the same league as coke (multiple national campaigns a year).
I would guess that at least 80% of people off the street would only be able to name advertised carbonated beverages. In that case, yes I think you are special.
Hence, the mnm project[1] (open source client & server) and TMTP[2][3].
[2] https://github.com/networkimprov/mnm/blob/master/Protocol.md
This strikes me as a cure worse than the disease. There’s a strong social need for people—especially those who are public figures or soliciting job offers—to be reachable by “never before seen” contacts.
There’s also a strong social need to allow people to send emails from self-provided (I.e. unverified) names or identities, given the currently burdensome process of getting “verified”.
I think you could argue that there’s an opportunity to move business email to “real ID”-verified identities (e.g. with SMIME), but I struggle to see how that’s a problem with SMTP or how replacing the protocol will help there.
All the scam and phishing mails I saw in my whole internet career were somewhere between totally obvious and embarrasingly blunt.
I can't agree with your assessment. If someone is naïve, they are at risk. Same applies for overconfidence. These are personality traits which are easily exploited. In real life as well as on the Internet. We cant protect everyone from everything. Neither in healthcare nor in VR.
That's because you have never been targeted. It's that simple.
There is a small segment of society who are: a) savvy, and b) not actively engaged in commerce/business/community/career/friends/family, so any solicitation over email is likely suspicious.
Everyone else is at some level of risk. And sometimes it only takes one failure.
Had the email come after I had learned the name of the new accounting firm, I never would have even clicked on the link.
And you can pick them up 99 times out of 100. But that 100th time, you're tired, rushing to get out the door, etc. and they get you.
I'm definitely more cautious than I was when phishing was just starting to be a big thing. Back then I don't think I ever fell for anything but there was once or twice when I wasn't really thinking and started down the path of providing information.
If it fooled you well enough you might not have noticed you were scammed.
Scams run from laughably blunt like the Nigerian prince to remarkably close to the real thing, like the callcentre that rang me pretending to sell phone contract upgrades that used exactly the same crap phone sales techniques my actual network used when they (coincidentally) called me a week later, and had a 1-letter different email address with the URL redirecting to the same website
The spoof was believable at first glance. It used the CEOs actual first name and obscured the actual source e-mail address with his company e-mail as the name. What should have given the engineer pause (among other things) was the context. There was no reason that the CEO would ask an engineer to do this task at my company. Nonetheless, the engineer was perhaps overly deferential to the chain of command and the suspicion didn't emerge until he had embarrassed himself.
If you can't be so direct with your boss, find another job.
Could have probably gotten 4 times $50 out of me though.
I was shocked that a company as small as ours was targeted, this phishing attempt was clearly not bot generated and the English in the email was very good, the only thing that was fishy was the request for gift cards.
Maybe not but you will. If you live long enough you will suffer inevitable cognitive decline until one day you will be vulnerable to such a scam. We all will. No amount of good diet, meditation, fish oil and exercise will keep that from happening.
Emacs, SSH, tmux, old fashioned email (text only) and a linux virtual console is all I need to be productive, fast and especially happy.
A big part of what makes these attacks work is the tech stack in use on the recipients side. I recently heard about a Emotet attack, and was told "Well, you know, the problem is that Outlook only shows the name but not the address by default". Oh well, what can you say about that?
Good for you for being so far off the map, though, that is a good protective measure.
I say "cross cultural" but by that I also mean "cross domain" which is how financial scams can entrap victims who aren't familiar with the details of financial jargon.
It's also why people can believe conspiracy theories which are absurd to someone familiar with the domain.
I'm interested in seeing the email address domain of the person who phished this author. And other specific details about the conversation-- such as screenshots and other evidence.
- "what appeared to be an official Harvard email ID" Did the phisher have a @harvard.edu sort of email address or not? I don't care about "what appeared to be" (i.e. insinuating the author interpreted the account to be official.) I want to know what the actual domain of the email address was -- not that in the author's opinion it seemed to not be fake.
- I know some professors have their own websites & use their own custom domains-- still, I'd see this as phishy unless it specifically came from a @harvard.edu account. And even then, the phisher could still have somehow accessed an available account. But, then I'd simply try to find their faculty page. Also, I would expect other people or gorup-email-accounts in HR to be CCed on the emails, not just some individual contacting me.
To be honest, I am surprised this author does not provide concrete details. She tells how things happened, and what steps she took. But provides no screenshots of her conversations, no specific details about the online personas of the phisher.
In which case-- this article is more of a "Don't get phished. But I won't show you how not to get phished and what it looks like when you're getting phished."
As the victim here - and as a journalist no less - it's in her own interest to present the attack as being incredibly sophisticated so as not to appear naive for being deceived. In reality, perhaps the attack was not as sophisticated as her narrative suggests.
Like you, I'd appreciate some more details.
We already had enough issues in infosec with companies claiming they're all attacked by "APT" and "state-sponsored actor". It just seems an easy way to dodge embarrassment and looking silly.
Of course, there are real cases where the person/company may actually be a victim of a sophisticated phishing attack (or APT/state-sponsored attack, etc) but the terms lose their weight when they are being thrown around like this.
edit: nevermind I've read the other replies and it's not that easy
I second you. This being the Hacker news I'm really interested in how the phishing worked and the postmortem of the scam. This is a golden opportunity to learn about such high profile attempts, but no one's talking about it. It's sad to see that neither the author, nor her detractors are making any attempt to analyze the situation rationally.
This, 100%. Just about every university in the US has a policy that all official school business must be communicated through your institutional email address- be it a question about the class or setting up an appointment for office hours. Most of my instructors have explicitly told us they will ignore any emails not sent from an @uni.edu email.
On a different note, how many schools set up a different email address structure for students versus faculty/staff? For my community college, students were first.last@g.communitycollege.edu and at my current uni students are FirstLast@my.university.edu. Is this standard practice?
The fact of the matter is that when joining a new institution one lacks the contacts and the context to discern normal institutional behavior because it so often deviates from (seemingly) ordinary, sane human behavior even when nothing is wrong. Having autism, no part of my mind is naturally attempting to cover up this discrepancy: it remains jarring until I manage to "manually" reset expectations.
That was the case for me at a couple of very early jobs in my career, but hasn’t been the case for the last couple of decades. New jobs come by way of old colleagues, friends, etc. in such a way that I’m basically never walking in to a completely unknown situation.
If you’re not great at relationship maintenance, use something like LinkedIn. Reach out to former coworkers who you worked well with or got along with, and ask about jobs. Odds are very high that they’d like to work with you again, and will get a referral bonus if it happens!
I just saw this tweet from someone senior at her former employer about how she uploaded a reference letter to an official-looking site but again, no screenshot or URL referenced.
They've gotten pretty good at crafting domains this way.
I suspect it is quite easy to make it look like many people from an institution are in a thread and a passive participant is an email address from a 3rd party job portal.
*Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
Edit: You added
> *Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
after my reply. I’m not sure how it is relevant to your claim that “alumni are often allowed to keep their addresses”. In fact the question doesn’t make any sense to me; I’m not gonna accept an MIT job offer from an alum.mit.edu address (or more relevant to me, alumni.stanford.edu/alumni.princeton.edu), regardless of network culture.
Edit 2: Reread your question and realized you were implying that MIT "recently" allowed alumni to keep @mit.edu addresses. Well, you'll need to show some proof.
This approach to identifying phishing is ultimately insufficient.
If that is so... so what? Plenty of organizations use different domains. Fidelity staff uses "frm.com"-- as an example-- while most customers know them as fidelity.com.
This could be something as simple as "someone@harvard-faculty.org".
For the recipient, this is effectively indistinguishable from a legit address. Not just because people are unsophisticated, but because many orgs really do use this sort of ancillary domain for conducting real business.
I've seen Fortune 50 corps, hospitals, and banks make this mistake.
Even if Harvard does not, has not, and will not ever make this mistake, an outsider would not be surprised to see it.
But the senders were not at Harvard, so it's very likely that they did not do so. And they would not need to do so, for their purpose.
This seems more like a targeted public embarrassment operation than an attempt at identity theft. Objectively, Nidhi made a ton of elementary mistakes that would be inexcusable for a journalist. This includes non-technological mistakes such as not contacting the Dean or prospective collaborators who presumably voted to have her on the faculty. There is an immense amount of hubris on display as well. That being said, the scammers were incredibly sophisticated and committed to the ruse.
Either ways, this sets a bad precedent. The internet allows for sophisticated scams like never seen before. A public embarrassment in the world of twitter can easily end careers.
I hope she finds some quiet in the midst of this public show where she has been made an unwilling jester. She should have handled this in private. Now that it is out on Twitter, trolls will make sure she never forgets what I presume has been incredibly traumatic.
This "phishing" is suspected to be a cover up for her own fraud getting caught.
Indian English Journalism is a farce.
They are exceptions, but it is an exception proves the rule sort of thing (Old Indian Express, The Print, Caravan)
Is there anything major you think she's done in her career that makes you say that?
The Indian English news media is consumed by an incredibly small fraction of the population. Nepotism is rampant and tiny cliques determine your fate. While Hindi media affects politics, English media affects global outlook and economics. They wield a disportionate power for their size and this power is lent to them because the West reads these outlets.
This made it the one that was most important & possible to control. The Indian English press rose in the era of Congress domination. These select few journalists, all owe their fates and meteoric rise to currying favor with the Gandhis and the bias shows. There is also a strong faux-left bias (Vox esque) but I would not blame them for it if they were transparent about it. Their 30 year track record on the Gandhi Family, Anything Hinduism related and Communists is proof of it. It is no surprise that Narendra Modi had a US visa ban, but terrorists and genociders from India and around the world never were.
These people live their lives out of Luthyens Delhi, completely out of touch with India. Their bad takes are never scrutinized, because the West and hyper-urban Indians have no idea what the rest of India looks like. Lastly, there is an offensive level of Elitism and need to associate with the Elites (NYT, WaPo, UN, Diplomats and the Glitterati) that is completely absent from Hindi media. This debacle epitomizes it.
Their opinions appear to be handed down from NYT and college campuses. They never bite the hand that feeds them and worst of all, they like to act smart while making lazy commentary.
Recently,I have been digging what ThePrint and Caravan magazine have been producing. Both are run on subscription models (yay) and take journalistic values seriously. Even when I disagree with them, I get something useful out of it.
TL;DR: Old Indian English Media is like MSNBC, Vox & CNN, but shallower, more elitist and nepotistic.
I'm sure this was an opportunity of a life time-- not enough of one to come off as totally implausible, but enough to paper over some of the red flags. Most scams are obvious in hindsight and from an external view.
Believing that you couldn't fall for a scam is probably one of the best ways to increase your vulnerability.
http://www.gelfmagazine.com/archives/nasas_prodigy_takes_ind...
This is exactly what it feels like to me.
You either know about the "IT cell" or please google it ... all the links on it are non-authoritative.
Assuming the scammers are Indian, and the victim would be expecting some Americans interviewing her, I wonder how they scammers got some Americans to join in the scam. Hire some American actors and tell them it's for a prank TV show maybe?
"We want to hire you for an HR job, please show us your skills by practicing with this woman."
Before you judge too harshly, keep in mind that often the people affected by this often aren’t very technical, don’t know what to look for when it comes to phishing, and are just doing what comes naturally in the situation. The scammers in this case are obviously at least somewhat technical and have a huge advantage in terms of being able to scattershot communicate with a very large group of people (potentially millions, although more likely 10’s of thousands in the case I describe). Also, while I’m sure no one reading this has ever been phished (cough), it has been _repeatedly_ found that phishing is effective, even for highly technical audiences. When it comes to recruiting, it is all too plausible that the person you’re interacting with doesn’t work for the company you’re “interviewing” with, and many recruiters start a conversation not even revealing who they recruit for. In fact, there are recruiting agencies that may as well be phishing organizations, because they will claim to have a role simply to get your resume and then, once they have your information, will start shopping it to companies in an attempt to get paid.
In short, I have a ton of sympathy for people affected by this, and think the assholes who do this kind of thing are pretty much evil.
Putting that aside, she should be equally blamed for falling for it despite being a fact checker for 21 years and also attending seminars, advisory meetings, talks and interviews as "Harvard Professor" without even going to a lecture hall once.
Here she is hijacking an event for aspiring journalists to try and interview Barack Obama, who sees through this and publicly shames her:
https://twitter.com/rose_k01/status/1350053978403291138
There are multiple interviews of her talking about her upcoming appointment, her class structures, here (non-existent) syllabus.
It seems like another possible interpretation of the events is that she made this all up, then blamed it all on a vague "phishing attack" to defuse any responsibility. In the months prior, her career received a boost from all the media attention. Now, she also has some level of additional fame, that while not exactly positive, could help her launch into the next phase of her aspirations
I find it hard to believe a journalist with 21 years of experience wasn't aware of this. When someone reaches out to me regarding a new job opportunity, I always do some basic research.
I also wonder what degree of ego played into this.
Who does Harvard contact out of the blue? If they contacted me out of the blue by email my first thought would be "Why would they contact me-- who am I? What have I accomplished that I would be on the radar that people are talking about me at Harvard to the point where I am invited to interview?"
To me, that would be phishy-- Unless I was some award winning, well-published, and/or well-credentialed journalist.
- Looking on Amazon, I see 1 book by this author: "Left, Right and Centre: The Idea of India". I also see a blank LinkedIn page, which mentions she lives in India.
- On Wikipedia, I see she has " done documentaries from Pakistan-administered Kashmir, Tibet and the United Kingdom after the train bombings." and "has been the diplomatic correspondent of NDTV 24x7, which is an English language television channel that carries news and current affairs in India, owned by New Delhi Television Ltd network.": https://en.wikipedia.org/wiki/Nidhi_Razdan
Those aren't trivial accomplishments. But I don't know that they represent the pinnacle of journalistic achievement to the degree that Harvard would reach out, out of the blue.
https://www.youtube.com/watch?v=SzCcVGbO9rw - Interview with Raghuram Rajan, who was the Governor of Reserve bank of India, was chief economist of IMF, and now a professor in US
https://www.youtube.com/watch?v=p1qS4gdutso - Interview with a maverick political consultant, kinda like Frank Luntz of India
https://www.youtube.com/watch?v=n6lolKKm2LU - Interview with Saudia Arabia foreign minister
I am sure I can find more examples, but the point is that during a 21 year career, of which a few years as a prime time host, you build a lot of network, you get a lot of local awards, that when a US school comes fawning, it may be a small surprise, but you take it in the stride.
Raghuram Rajan has been a professor at the University of Chicago since 1997 except for a 3 year period from 2003-2006 when he served at the IMF. He was given a "public service" sabbatical from the University of Chicago to serve at the RBI.
https://www.chicagobooth.edu/-/media/faculty/raghuram-rajan/...
> Contrary to what many are tweeting, Harvard has a school called the Extension School offering a Journalism Degree Programme[1]. The actual programme is called the Master of Liberal Arts, Journalism degree.
1. https://www.extension.harvard.edu/academics/graduate-degrees...
Or maybe it wasn't about the money? Maybe she was targetted specifically for her previous roles and knowledge?
Attack was very sophisticated.
Story is very fishy.
I think it is equally easy to imagine that she made it up (and pressured co-workers to lie?) to falsely claim harvard credentials with a good out as it is to imagine that a political organization wanted to discredit a journalist and get her to resign, probably expecting her to go quietly.
Since politicians are being given special access to advanced phishing, I think it is prudent to treat the story as real. How can this not raise demand for similar attacks using software from the US/Israeli/Italian/etc firms that specialize in state sponsored crime?
It didn't start there though. The offer letter supposedly came in January 2020 when things were perfectly normal in the vast majority of the world; I was traveling around Europe without a thought of pandemics at that time.
It seems a little weird that there would be a job offer after just a 90 minute phone interview. And moving halfway around the world seems a pretty big deal and one would think someone in that situation would be looking for a bit more motion on the logistics. On the other hand, we're talking Harvard Extension School and she's in India so maybe not a complete red flag especially given she had some apparent prior contact with the school. But certainly the pandemic allowed them to string things out for whatever reason.
It does seem as if there are different stories floating around though.
https://www.npr.org/2020/12/18/944594193/new-york-times-retr...
What a roller coaster of emotion that Podcast was!
And no, it wasn't particularily interesting since I am incapable of falling for optical illusions.
It explained the concept of attention blindness. If you look for something else, then you may miss the gorilla in the room, even though it is as obvious as can be. Same goes for job offers. You're primarily looking to get the great job, and involuntarily and unknowingly enter a kind of tunnel vision.
Since everyone seems to beat the same horse, I feel like I have to declare that of course, everyone can make a slip up, nobody is free of failure, we are all human. This is so obvious that I feel stupid stating it.
But we're talking about a journalist. The protagonists of a story do have an influence on its perception.
it would have been interesting if she would have shared exactly what that email address was. Was it hr@harvard.com or maybe hr@harverd.com? I doubt that it was hr@<something>.edu since it is hard to register .edu domains. But if someone did, that would be news to me.
Note the bad pun Harvard uses: "post"
Or you could get an address (deceptively or via hijack) on an subdomain run by a student group.
A particularly sneaky scammer without access to Harvard mailboxes might register a plausible-sounding domain with an .ac TLD (which resembles the .ac reserved for universities in many national domain systems including the author's, but is actually a freely purchasable domain supposedly associated with Ascension Island)
Edit: I tried harvard-extension.school in the browser, it redirected me to http:harvard-education.edu (not https!), which seems to be a clone of extension.harvard.edu . The WHOIS records of harvard-extension.school/.education are pretty new (registered last year), and they're registered on GoDaddy and 1API GmbH respectively. A Germany-based registrar? Would Harvard use them?
Spear-phishing, in contrast, targets a specific audience with a message that includes specific details that make it more convincing - your boss's name, company, job title, bank account number, mortgage loan start date, health provider name, etc. The more specific, the better. These can be very hard to detect. If I've just been to the doctor, I'm expecting to get an email about a hospital bill, and I'm pretty confident that the hospital's online payment site will look like it hasn't been updated from the 90s. TBH, half the time I'm paying a medical bill online, I'm crossing my fingers that it's actually going to the right place...
edit: grammatical
Twitter is filled with BJP IT Cell bots and miscreants. I wouldn't expect less.
Can you say with a straight face that Republic TV is not biased ? Or India TV ?
To get strung along for over a year, throwing away that much time and energy, must feel devastating.
I immediately alerted the dean to warn everyone.
If a CEO is gonna want me fired because I'm being skeptical of the veracity of an email, I wouldn't want to work at such a place.
To those who are downvoting this because of the misleading comment below, note that she claimed on Twitter to be joining the Harvard Faculty of Arts and Sciences, not the Harvard Extension School. Nobody becomes an Associate Professor at the Harvard FAS without a PhD.
Source: https://twitter.com/Nidhi/status/1271705895437651968
ADDED: It certainly seems as if the story has changed from something implausible to something vaguely understandable.
"After 21 years at NDTV, I am changing direction and moving on. Later this year, I start as an Associate Professor teaching journalism as part of Harvard University’s Faculty of Arts and Sciences."
Nobody is joining Harvard's FAS as as an Associate Professor without a PhD.
Teju* Cole, Gore Vidal Professor of the Practice of Creative Writing (an endowed professorship, no less! With only an MA and mphil!) https://english.fas.harvard.edu/people/teju-cole
Michael Pollan, Lewis K. Chan Arts Lecturer and Professor of the Practice Non-Fiction (also a professor of journalism at Berkeley! With only an MA!) https://english.fas.harvard.edu/people/michael-pollan
HBS likewise has business practitioners without phds on faculty. Their expertise is of value regardless of on-paper credentials.
These are two very well respected writers. Often, in more research oriented disciplines, the “experts” have phds, by necessity. But especially for applied humanities like creative writing and journalism, the experts w the most experience quite often _do not_ have doctorates, and that does nothing to diminish their expertise or professional credentials.
I’m not here to debate this specific claim of phishing, but this is just factually false, _especially_ for applied / practiced humanities. Here are two examples of well respected authors / journalists who are more senior than associate prof at Harvard’s FAS...and this was on just the first link in my first search:
Teju* Cole, Gore Vidal Professor of the Practice of Creative Writing (an endowed professorship, no less! With only an MA and mphil!) https://english.fas.harvard.edu/people/teju-cole
Michael Pollan, Lewis K. Chan Arts Lecturer and Professor of the Practice Non-Fiction (also a professor of journalism at Berkeley! With only an MA!) https://english.fas.harvard.edu/people/michael-pollan
HBS likewise has business practitioners without phds on faculty. Their expertise is of value regardless of on-paper credentials.
These are two very well respected writers. Often, in more research oriented disciplines, the “experts” have phds, by necessity. But especially for applied humanities like creative writing and journalism, the experts w the most experience quite often _do not_ have doctorates, and that does nothing to diminish their expertise or professional credentials.
That said, yes it's extremely misleading for a DCE instructor to call themselves an FAS professor. This sort of thing does happen at all top tier schools' extension programs, though far more often it's done by students rather than instructors.
I’m not here to debate this specific claim of phishing, but this is just factually false, _especially_ for applied / practiced humanities. Here are two examples of well respected authors / journalists who are more senior than associate prof at Harvard’s FAS...and this was on just the first link in my first search:
Teju* Cole, Gore Vidal Professor of the Practice of Creative Writing (an endowed professorship, no less! With only an MA and mphil!) https://english.fas.harvard.edu/people/teju-cole
Michael Pollan, Lewis K. Chan Arts Lecturer and Professor of the Practice Non-Fiction (also a professor of journalism at Berkeley! With only an MA!) https://english.fas.harvard.edu/people/michael-pollan
HBS likewise has business practitioners without phds on faculty. Their expertise is of value regardless of on-paper credentials.
These are two very well respected writers. Often, in more research oriented disciplines, the “experts” have phds, by necessity. But especially for applied humanities like creative writing and journalism, the experts w the most experience quite often _do not_ have doctorates, and that does nothing to diminish their expertise or professional credentials.
I asked him about it 10 minutes later and was shocked he had submitted all his account information from a text alert.
“You do realize you just gave all your account information to a scammer in a phishing attack I hope.”
Thankfully he was able to change account information within minutes and no funds were lost.
Moral: check in with your parents, people around the world are trying to scam them weekly.
If they are all programmed to extract funds through conversation, how will we prevent this?
‘I had been told a work visa had been issued in the US for me which would be sent to me only when travel was required.‘
I think this should have been a major red flag. Work visas are not issued like that. I don’t understand why you wouldn’t interact with an embassy for visa issuance.
I'd love more details, because there's not much to learn here. I walk away from the article with no idea about novel defensive strategies people need to take and no idea what we as technologists can do to help prevent this in the future.
That's their classic way of burning her for burning them.
Having said that, I learnt the same lesson as well a few years ago. Never quit your current unless you're 101% sure your next job is waiting for you and all the due process is taken care of.
Anything unique about this that explains the blast radius of this news?
I hope you wouldn't apply that logic to victims of other non-online crimes.
Anyway, separately, she addresses that in her article, convincingly I thought. Plus she's brave and helping others to write about this (which victim blaming doesn't encourage).
At some universities, it’s possible to create email aliases at your .edu domain, so it’s possible that the scammer had access to one or more convincing email addresses.
The article doesn’t say that the emails received were “@harvard.edu” only that they appeared to be valid Harvard ids. That means she made a judgement call that the email were legitimate, but it doesn’t give very many technical details on what she judged that call on.
This sounds exactly like the kind of job opportunity that's meant to come about by networking, getting your name out there, public speaking and so on. We are often told that this is how the best jobs are found.