Bad actors try to get into your account for three main reasons:
- To send spam and phishing messages from your Bmail account.
- To change your direct deposit and steal your paycheck.
- To steal your Social Security Number and private information.
Here's the news. Your account was not hacked. Hacking is a type of compromise where bad people use sophisticated computer programs to guess your password. That's not what happened to you. Your account was phished. Phishing is an attempt to steal your password by sending you fake email messages or directing you to fake web pages. Phishing only works if you go to a fake page and type in your password. And you did!
If IT staff have already detected that your account was compromised, then your password has already been reset. When directed, you must go to Bucknell Account Management and set up a new Bucknell password. When you logon for first time after changing your password, please check the following locations to verify that your account is functioning properly.
If you think your account is compromised, contact the Tech Desk immediately!
Secure Your Password
- Change your Bucknell password immediately.
- Go to Bucknell Account Management at bam.bucknell.edu.
- Create a new password.
Secure Your Duo Security Multifactor Authentication
- Login to Duo Security.
- Verify that you recognize every device or technique used in Duo Security.
- Remove any devices you do not recognize or own.
Secure Your Paycheck
- Login to Workday.
- Go to your direct deposit.
- Verify that the account information in Workday is accurate for your checking account. Remove any accounts you do not recognize or own.
- When you are in Workday, verify that your personal email address and personal phone number are correct.
- Report any intrusions into Workday immediately.
Secure Your Bmail
- Google Security Check - Review your security settings in your account.
- Devices - Review the devices that are signed into your account. Remove any devices you do not recognize.
- Recent security activity - Review the security activity in your account from the last 28 days. If you see any activity you do not recognize, click See unfamiliar activity and follow the steps to secure your account.
- Sign-in & recovery - Verify your recovery email and trusted mobile devices. If you do not recognize these settings, make corrections immediately.
- Third-party access - Review the apps that have access to your account. These apps may be installed in Mail, Calendar, Drive, or Chrome. Note: Read&Write by Texthelp is approved and automatically installed for any user logged into Chrome.
- Gmail settings - Review any sensitive settings. If you do not recognize a sensitive setting, remove it.
- General - Click on the Gear in the top right corner of your Inbox. Select Settings from the dropdown menu.
- Signature - On the General tab, scroll down to Signature. If the signature is not your own, delete it. Pay special attention to any links included in your signature.
- Vacation Responder - Scroll down to the Vacation responder and if the message is not your own, delete it.
- Accounts - Select the Accounts tab.
- Send mail as - If a name other than your own appears, delete it or set a new default.
- Check mail from other accounts - If an account you do not own appears in the POP3 section, delete it.
- Grant access to your account - If an account you do not recognize appears in this section, delete it.
- Filters - Select the Filters tab. If you see any filters you did not create or you do not recognize, delete them. The bad actors may create filters that automatically move all the messages they send and receive in your account to the trash. They may also create filters that move all notifications from Library & IT to the trash.
- Forwarding and POP/IMAP - Select the Forwarding and POP/IMAP tab.
- Forwarding - Delete any forwarding addresses you do not own by selecting "Disable forwarding " - This step is very important!!!
- POP - If you do not use POP (and you probably don't), disable it.
- IMAP - If you do not use IMAP, disable it.
- Contacts - In the top left corner of Bmail, click the down arrow next to Mail. Select Contacts. If you see contacts you do not recognize, follow the instructions to Restore Contacts to an earlier point in time.
- Sent Mail - In your label list (also known as mailboxes or folders) locate Sent Mail. Inspect the list to see if there are sent messages you do not recognize. Delete any unrecognized sent messages.
- Calendar - Open your Calendar sharing to verify that you recognize everyone who has permission to view or edit your calendar. If there are any names or usernames you do not recognize, remove them from sharing.
- Google Sites - Go to Google Sites and verify that all the sites in your account are really yours. If there are any sites that you did not create, delete them.
- Authorized Devices - Verify that you own or control all the devices that are accessing your account.
- Recent Activity - Over the next few days and weeks, continue to check your Recent Activity.
- Phishing - Never respond to email messages that try to scare you into giving your password to dangerous people. If you get a message like this, use the Report Phishing button to tell Google about the fake email. Please forward a copy of the message to the Tech Desk - Library & IT staff want to review any potential phishing messages you receive.
Shared Document Compromise
If your account was compromised because you clicked on a shared document in a phishing message, follow these steps to remove the document and block the sender.
When someone outside your domain shares a file directly with your Google Workspace account, it appears in your "Shared with me" section in Google Drive.
Here are the best ways to remove or block these files, depending on what you want to achieve:
Method 1: Remove the File from "Shared with me"
Removing the file hides it from your Google Drive view.
- Open Google Drive (
drive.google.com).
- In the left navigation menu, click Shared with me.
- Right-click the file (or select it and click the three dots menu icon at the top right).
- Select Remove.
Note: This removes the file from your view, but it does not delete the file for the owner or prevent them from sharing with you again in the future.
Method 2: Block the External Owner (Recommended for Unwanted or Spam Shares)
If the file is unsolicited, spam, or sent by someone you don't want sharing files with you, blocking the user will remove all files shared by them and prevent them from sharing files with you going forward.
- Go to Google Drive (
drive.google.com).
- Right-click the file (or open the three dots menu).
- Select Block [owner's email] (or Block user).
- Confirm by clicking Block in the pop-up window.
What happens when you block someone:
- The file immediately disappears from your Drive.
- The owner can no longer share files or folders with you.
- The owner will lose access to files you have shared with them.
Method 3: Report as Spam
If the file contains phishing, malicious links, or unwanted marketing:
- Right-click the file in Shared with me.
- Select Report spam (or Report abuse).
- Confirm the report.
This removes the file from your Drive and alerts Google's security systems.
Secure Other Systems
- Login to any other Bucknell systems that contain sensitive or confidential information. Verify that each system has not been changed while your account was compromised. For example, login to Workday to verify that your direct deposit for your paycheck is unchanged. If you see signs of compromise in other systems, contact the Tech Desk or the other relevant department.
- Change all passwords you may have used during this time in any personal or non-Bucknell sites or accounts. For example, if you may need to change your passwords for banking, credit cards, shopping, etc. if you access any of these resources while your Bucknell account was compromised.