To content

Potential spear phishing danger

We have received information that the CRM solution provider CAS Software AG was recently the victim of a cyber attack. CAS' own operating infrastructure was affected, while the data centers for customer solutions (e.g. SmartWe) remained unaffected. These systems continue to operate without disruption and there are no indications of unauthorized access.

We would particularly like to point out that in the course of this attack, emails were removed from the CAS systems. This could lead to an increase in spear phishing attacks against TU Dortmund University in the future that relate to a past interaction with CAS Software AG. Unfortunately, it is a common practice that such data, together with historical correspondence content, provides the optimal breeding ground for sophisticated, individualized phishing campaigns.

Spear phishing is more personalized and targets specific individuals. Such emails contain content from past, genuine email communication and therefore appear confidential and legitimate. Please remain vigilant when dealing with emails in future, even if the sender is supposedly known and emails have a familiar subject or email content.

IT Security and Data Protection & SIC Department