Duo has also introduced a new Self-Service Device Management (SSDM) portal to allow users to access the device management interface directly. This will allow users to add/remove devices without the help of IT/Help Desk staff. To access Duo SSDM, please visit https://yorku.login.duosecurity.com/ and login with your Passport York credentials. Once inside the portal, users will […]
Advisories & Alerts
Phish Alert - Notification of Student/Staffs Account Deactivation
A phishing email is currently being circulated among faculty, staff, and students. The email, titled "Notification of Student/Staffs Account Deactivation", claims to be from YorkU IT Admin and prompts recipients to submit personal information to prevent account deactivation. Key details of the phishing email: From: York U IT Admin <jana.jakesova@KCHMPPCZ.onmicrosoft.com> Subject: Notification of Student/Staffs Account […]
New Duo Security Enhancements Coming to York
As part of planned updates to York’s current Duo 2FA service, UIT will be deploying an extra layer of security through the implementation of Duo Verified Push, Time-Based One-Time Password (TOTP) codes, and the Self-Service Device Management (SSDM) portal. What’s Changing? Verified Push will ask you to enter a 3-digit code during the login process. […]
Job Scam - Ontario Universities Students Jobs Placement 2024 Fall Semester
We have identified another targeted phishing email with the subject line "Ontario Universities Students Jobs Placement 2024 Fall Semester". The email includes a PDF attachment and asks recipients to contact hr@careers-opinionoutpost.com. Do not respond, open the PDF, or engage with the email. This is a scam aimed at financially defraud you. If you have already […]
Job Scam - York U: Jobs Placement Fall 2024 Semester
We have identified a targeted phishing email sent from a compromised university account. The email includes a PDF attachment and asks recipients to contact hr@careers-opinionoutpost.com. Do not respond, open the PDF, or engage with the email. This is a scam aimed at financially defraud you. If you have already responded to this scam: Stop all […]
Scam Alert - Your Microsoft order on Emails Abusing an Official Microsoft Email
York University and other organizations are experiencing an ongoing scam campaign leveraging an official Microsoft email address to send fraudulent order confirmations to users. The campaign abuses the official microsoft-noreply@microsoft.com email address to send fraudulent purchase notifications to York University's community. The objective of this scam is to get recipients to call the scammers' phone […]
Phishing Alert - NOTICE BY ADMIN VERIFY YOUR ACCOUNT (Please Verify your account immediately to avoid Deactivation)!! / VIRTUAL PERSONAL ASSITANT JOB (REMOTE)
A targeted phishing email with the subject lines "NOTICE BY ADMIN VERIFY YOUR ACCOUNT (Please Verify your account immediately to avoid Deactivation)!!" OR "VIRTUAL PERSONAL ASSITANT JOB (REMOTE)" has been spotted. It's purpose is to trick recipients. The link redirects users to a Google Form that requests your Email Address, Password and Duo Passcode. Please note […]
Passport York password complexity requirements update
Passport York uses a password strength estimator to ensure that users set strong, difficult to crack passwords for their account. This is done in order to increase the security of their various accounts at the University. The estimator analyzes passwords and assigns them a score based on their complexity. We have increased the score required […]
Phishing Alert - * Release Held Messages * / You have messages on hold'
A targeted phishing email with the subject lines "* Release Held Messages *" OR "You have messages on hold'" has been spotted. The phishing email was sent from a compromised account unrelated to York University. The emails included a link to a fake site resembling a Passport York Login page, asking recipients to provide their […]
Job Scam Alert - Virtual Assistant Needed
A fraudulent job scam email with the subject line "Virtual Assistant Needed" was sent from a York compromised account to various mailboxes. The Information Security team has taken action to remove the fraudulent messages. If you receive similar messages, please report it immediately […]