‘Department of Education’ Phishing Scam

Fraudsters are initially calling education establishments claiming to be from the Department of Education. They then ask to be given the personal email and/or phone number of the head teacher/financial administrator. The fraudsters claim that they need to send guidance forms to the head teacher (these so far have varied from exam guidance to mental health assessments). The scammers on the phone will claim that they need to send these documents directly to the head teacher and not to a generic school inbox, using the argument that they contain sensitive information.

The emails will include an attachment – a .zip file (potentially masked as an Excel or Word document). This attachment will contain ransomware, that once downloaded will encrypt files and demand money (up to £8000) to recover the files.

It should be noted that similar scam attempts have been made recently by fraudsters claiming to be from the Department for Work and Pensions and telecoms providers (in this case they need to speak to the head teacher about ‘internet systems’).

Prevention Advice

Having up-to-date virus protection is essential; however it will not always prevent you from becoming infected.

Please consider the following actions:

  • Although the scammers may know personal details about the head teacher and use these to convince you they are a real employee, be mindful of where these have been obtained from, are these listed on your public facing website?
  • Please note that the “Department of Education” is not a real government department (the real name is the “Department for Education”).
  • Don’t click on links or open any attachments you receive in unsolicited emails or SMS messages. Remember that fraudsters can ‘spoof’ an email address to make it look like one used by someone you trust. If you are unsure, check the email header to identify the true source of communication.
  • Always install software updates as soon as they become available. Whether you are updating the operating system or an application, the update will often include fixes for critical security vulnerabilities.
  • Create regular backups of your important files to an external hard drive, memory stick or online storage provider. It’s important that the device you back up to aren’t left connected to your computer as any malware infection could spread to that too.
  • Do not pay extortion demands as this only feeds into criminals’ hands, and there’s no guarantee that access to your files will be restored if you do pay.
  • If you think your bank details have been compromised, you should immediately contact your bank.
  • If you have been affected by this, or any other scam, report it to Action Fraud by calling 0300 123 2040, or visiting actionfraud.police.uk

About suffolktradingstandards
Suffolk Trading Standards is working towards creating and fair and safe trading environment. By creating empowered consumers, that are armed with the knowledge to stop 'rogue traders'.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: