<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Rant] Really annoying phishing attempts in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/805#M763</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Reporting it to the IT of the offending organisation is the best approach&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One can, of course, also email the offending account, as they may not be aware of the breach of their account.&lt;/P&gt;&lt;P&gt;I've over the years received masses of attempts using OneDrive as storage. Very few using Google Drive.&lt;/P&gt;&lt;P&gt;IT not responding to a breach is very poor form. I'd be very happy if someone informed me of such a situation.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2023 14:22:29 GMT</pubDate>
    <dc:creator>Kim_Nilsson</dc:creator>
    <dc:date>2023-09-05T14:22:29Z</dc:date>
    <item>
      <title>[Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/804#M762</link>
      <description>&lt;P&gt;I'm not sure what it means overall (probably that these entities have a compromised account) but it's rather annoying when external schools send Google Docs to some of our users like "Document shared with you 'Employee Form.docx'"&lt;/P&gt;&lt;P&gt;How do you normally handle these? So far I've Googled their IT Director or similar positions notifying them of the potential compromised accounts. I never hear back. Otherwise if I can't find an IT resource, if the schools website has a "Contact Us" I let them know via that.&lt;/P&gt;&lt;P&gt;I've also recently even been receiving these type of emails (Google Docs shared/notifications) to my personal Gmail account. I hope Google knows that it's probably one of the largest distributors of Spam and Phishing attempts out there...you'd think they'd somehow combat this type of stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/End rant&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:17:37 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/804#M762</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-05T14:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/805#M763</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Reporting it to the IT of the offending organisation is the best approach&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One can, of course, also email the offending account, as they may not be aware of the breach of their account.&lt;/P&gt;&lt;P&gt;I've over the years received masses of attempts using OneDrive as storage. Very few using Google Drive.&lt;/P&gt;&lt;P&gt;IT not responding to a breach is very poor form. I'd be very happy if someone informed me of such a situation.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:22:29 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/805#M763</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-05T14:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/807#M764</link>
      <description>&lt;P&gt;Part of me thinks replying/emailing the individual back may also notify the bad-actors which in turn may attempt to do further harm (more emails, cover tracks, etc.), hence my reasoning to only go to their IT department so they can get any logs they may need.&lt;/P&gt;&lt;P&gt;I can see your point though as most likely they're totally unaware. We're a part of an ISAC group and receive periodic compromised account passwords lists/alerts, which is beneficial for our own users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:26:47 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/807#M764</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-05T14:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/808#M765</link>
      <description>&lt;P&gt;Yup, that could also happen, but if the IT person doesn't get back to you, I wouldn't let the account keep spamming your users. If it's completely unrelated, then you can of course block it in Compliance or Routing.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:28:33 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/808#M765</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-05T14:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/809#M766</link>
      <description>&lt;P&gt;That is a valid point as well. I've created a compliance rule for another school that seems to be a frequent target to drop emails if from specific domain and subject contains XYZ. Can't full out block them because they appear to have actual communication with our institution.&lt;/P&gt;&lt;P&gt;I guess I my expectations might be too high, expecting a response of some kind&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:33:06 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/809#M766</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-05T14:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/810#M767</link>
      <description>&lt;P&gt;We typically reach out to the IT Director and so far, that has worked well for us.&amp;nbsp; &amp;nbsp;This happened to us as well and like Kim said, we were really happy that a nearby school let us know that one of our accounts had been compromised.&amp;nbsp; It's definitely frustrating though!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 18:13:58 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/810#M767</guid>
      <dc:creator>JimmyR</dc:creator>
      <dc:date>2023-09-05T18:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/830#M768</link>
      <description>&lt;P&gt;Are you notifying them via email or by phone? If the attempts stop then I'd assume they've taken care of things but might not hurt to reach out again, preferably by phone, to double check.&lt;/P&gt;&lt;P&gt;If it's a continuous issue and you keep getting no response then mayhaps it would be appropriate to start contacting front office/other administration members?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 17:31:54 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/830#M768</guid>
      <dc:creator>MattDPenn</dc:creator>
      <dc:date>2023-09-06T17:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/833#M769</link>
      <description>&lt;P&gt;I have only done email, but my manager has done phone calls. For one particular district/charter in Texas, it's a different account every few months.&lt;/P&gt;&lt;P&gt;More or less just venting&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 17:39:08 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/833#M769</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-06T17:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/842#M770</link>
      <description>&lt;P&gt;Might be worth looking into if there's a group/org to report them to. Like county level offices or something but I have no idea what the set up in Texas is like outside of what I hear in the news.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are some legitimate emails flowing between your schools (as mentioned in one of your replies) it might still be worth doing a full block of the domain so that the people that were communicating are forced to reach out via phone and maybe their complaints would help apply pressure. At the end of the day you gotta protect your users.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 20:31:10 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/842#M770</guid>
      <dc:creator>MattDPenn</dc:creator>
      <dc:date>2023-09-06T20:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1137#M771</link>
      <description>&lt;P&gt;Edit: they have another compromised account that sent us a Drive document&lt;/P&gt;&lt;P&gt;Update and I'm not sure it'll resolve the problem since it's a Drive sharing issue, not necessarily a Gmail issue:&lt;/P&gt;&lt;P&gt;In Gmail Compliance, I've blocked anything containing&amp;nbsp;@domain.tld (obviously substituted the real domain) of this school district. I've also went to their website and submitted a complaint via the "Contact us" page.&lt;/P&gt;&lt;P&gt;If there is a way to block all external domains from sharing stuff with us, is that possible via the Drive -&amp;gt; Sharing Settings -&amp;gt; Sharing Options -&amp;gt; ALLOWLISTED DOMAINS? If we change to the ALLOWELISTED DOMAINS, does that mean external entities not in the ALLOWLIST will be denied?&lt;/P&gt;&lt;P&gt;Google really has to do something. Not only are they the largest spam filtering company, they're also one of the largest proliferators of spam...&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 20:17:23 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1137#M771</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-26T20:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1149#M772</link>
      <description>&lt;P&gt;Yes, switching to allowlisted domains will accomplish exactly that, but only for&amp;nbsp;&lt;EM&gt;outgoing&lt;/EM&gt; sharing.&lt;/P&gt;&lt;P&gt;Just like there is a setting when allowing all sharing, there's one for &lt;EM&gt;incoming&lt;/EM&gt; sharing in the Allowed Domains section. You need to untick that box.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Block incoming sharing from unknown sources." style="width: 652px;"&gt;&lt;img src="https://www.googleforeducommunity.com/t5/image/serverpage/image-id/199i67138EE619AAFEC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Skärmavbild 2023-09-27 kl. 08.50.24.png" alt="Block incoming sharing from unknown sources." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Block incoming sharing from unknown sources.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then no unknown &lt;EM&gt;incoming&lt;/EM&gt; sharing will be allowed.&lt;/P&gt;&lt;P&gt;This can be set for the students' OU only, if you want, and even for a Group.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 06:53:18 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1149#M772</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-27T06:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: [Rant] Really annoying phishing attempts</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1159#M773</link>
      <description>&lt;P&gt;Perfect. We just put in on our change board for next week to discuss changing to this setting. The uptick in these successful Drive phishing attempts has increased and since Google isn't able/willing to help (via opening a case and providing all sorts of evidence and data), this is the only option we have to protect our users from a technical aspect&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 13:11:15 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Rant-Really-annoying-phishing-attempts/m-p/1159#M773</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-27T13:11:15Z</dc:date>
    </item>
  </channel>
</rss>

