Compromised Accounts

An account can be compromised in a variety of ways and quick action to prevent further damage is always required. If your information is known to criminals, they will attempt to use it to break into your other accounts or devices, so any breach of your account or personal information is serious and should be treated seriously.


What do I do after my account has been compromised?

Change your Olivet password

Immediately update your ONU password by visiting https://myaccount.microsoft.com. (refer to password tips below)

Change all of your other passwords

Update personal passwords (banking, shopping, social media) immediately by going to each source organization (refer to password tips below). You should do this from a known secure device since your device may be compromised and may pass the new passwords on to the attacker.

Check Email Rules

Oftentimes, when an account has been compromised, the attacker will often set up email and forwarding rules on the account to avoid any detection from the end-user.

Visit Outlook Rules for Steps on how to find and change rules.

View customized security info/training

ONU uses KnowBe4 to provide security info and training modules. Visit knowbe4.olivet.edu to see if any modules are available to you for more information

Scan for malware/spyware

Every device should be checked for malware, spyware and other malicious software. Alternatively, reset your device to a new state and rebuild it.  Contact your device manufacturer or a computer professional for assistance if needed.

You might think your account isn't important, but there are many ways that your account can be used by criminals for financial gain or otherwise. Even if you don't think you store anything private, there is significant value in the account itself to gain access to information of value. When an account is compromised, not only is sensitive data put at risk, the attacker gains access to computing resources that allow them to expand their attack. Here are a few things that criminals look for:

  • Information about you that can be used to steal your identity, commit fraud, and target your email contacts for phishing and fraud.
  • Information about you or others that can be used for extortion at a later date, or to combine with data from other sources to impersonate and manipulate a person's actions.
  • Access to your student or HR record, email, grades, direct deposit, tax information, etc.
  • Access the ONU network, processing power, storage and services that they can use to commit crimes against you or others.

How can my account get compromised?

Phishing

There are many variants of phishing messages that attempt to trick you into taking some sort of action. You should never confirm your identity in an email or provide confidential information to anyone over email.

Stolen Passwords

Passwords are stolen via many methods or can be cracked by trial and error...or simply just by knowing information about you.

Password Reuse

Using the same password on multiple accounts is a leading cause for account compromise. Attackers can harvest passwords via security leaks or past data breaches on external accounts then just try millions of combinations until they get in. 

  • Don't ever reuse your ONU password on another account. 
  • Be even more careful if an account uses your ONU email address as a username. If an attacker gets one, they can easily have access to the other.
Password Sharing

Don't ever share your passwords with anyone. Ever.

Some of your passwords may effectively be worth thousands of dollars or more.

Weak Password

Simple passwords are easy to break. Most of the time, attackers don't even need to break a simple password they just try a list of the most common passwords to get right in.

Unsecured Networks

Do not perform sensitive internet tasks on public public networks. Free WiFi is a great idea, but many networks are unsecured and any attacker on that network could intercept your internet traffic.

Malware

Viruses or scripts on websites or in attachments can infect your device and capture information that exists on the machine or as you enter information into other websites.

  • Opening any unknown attachment in an email, "lost" flash drives or on websites
  • Interacting with an infected phishing email
  • Visiting an infected website without realizing it was doing something malicious in the background
  • Interacting with a compromised social media post or account

Password Tips

DO Use passwords that are hard to guess but easy to remember

  • Use a "pass phrase" by stringing multiple words together in a way that you can remember without it being simple to guess.
  • Random passwords are the strongest.

DO Use combinations of characters

  • Use upper and lower case letters, numbers, symbols and special characters. Some sites don't allow specific characters, but use them wherever you can. 

DO Use longer passwords

  • Short, simple passwords are easy to hack, make it harder by making it longer than 10 characters.
    • Every character you add to your password makes it exponentially harder and harder to guess.

DO Use a password manager

  • A password manager can organize and assign complex passwords and help you keep a different one for every site. Common choices include:
    • LastPass
    • 1Password
    • KeePass
    • Dashlane,
    • Keeper

DO Use Multi-Factor Authentication (MFA, 2FA)

MFA can protect your account against attackers, even if they get your password. 

DON'T Use the same password in multiple places

Using the same password on multiple accounts is a leading cause for account compromise.  

DON'T Share your password. 

  • Don't ever reveal or share your password with anyone, ever, including co-workers, friends and family.
  • Don't enter your password on forms.
All passwords must be kept confidential; we will never ask for your password.

DON'T Store your password insecurely.

  • Don't use the remember password features on browsers.
  • Don't store passwords in a file on your computer or in the cloud. 
  • Don't store passwords in any program that isn't a secure password manager.

DON'T Keep using the same password.

  • If your password is new, reset or temporarily assigned, change it right away!
  • Adding a number to a previous password is a very bad practice.

Anatomy of a Bad Password

  • Names
    • your own
    • your parents
    • pets
    • friends
    • celebrities
  • Dates
    • anniversaries
    • famous years like 1776 or 1492
  • Phone Numbers
  • Addresses
  • Birthdays
  • Social security numbers
  • Drivers license numbers
  • License plate numbers.
  • Common pass phrases
    • let me in
    • open up
    • other similar phrases
  • The word password, pass, p@$$word or similar
  • Simple patterns
    • hahahahaha
    • qwerty123
    • asdfjkl
    • 12345678
  • Example passwords in a manual or in help guides (like this article).
  • Passwords you use anywhere else.
  • Password that you recycle or increment by a number or otherwise change only slightly.
  • Anything on this list (or slight variations) of the worst passwords: Most Common Passwords List

Need Help?

If you're having issues, contact the IT Help Desk:

(815) 939-5302 | it@olivet.edu

Print Article

Related Articles (2)

After changing your password, there are some things you need to do in order not to get locked out of your account.
How to get access to your account when you are having problems with the typical MFA prompts.