Cyber security and helping to protect our community

We are continuing to see an increase in sophisticated phishing attacks targeting universities.

Phishing attacks are constantly evolving, so making sure that your cyber security training is up to date remains a key part of your role in helping to protect yourself, fellow students and University staff. You can find the training modules on Teams and by searching for ‘MyCompliance’ in the apps tab.

You can also follow the five rules to stay safe:

  1. Don’t click on links in emails, instead hover your mouse over to see the web address
  2. Never give out your personal information
  3. Do not open attachments from people you don’t know, or if you weren’t expecting them
  4. Watch out for common phrases, often giving a short deadline to click on a link
  5. If in doubt, don’t do anything! Email phishingalerts@liverpool.ac.uk for advice about whether an email is malicious or not.

You can find more information about spam and phishing emails on our email security page.

Instructure cyber incident

Work has continued in relation to the Instructure (Canvas) cyber-security incident which took place in May.

More than 9,000 institutions globally were affected to some degree by this incident, and we have been working closely with Instructure to understand the specific data which may have been impacted at the University of Liverpool. This is still undergoing detailed analysis but may include:

  • Staff / student usernames
  • University contact details
  • Module information
  • Some messages sent and received in Canvas

Whilst this data was only accessed for a short period, and has since been deleted or destroyed, staff and students are encouraged to continue to be vigilant to phishing, particularly where University contact details are used, as a precaution. For helpful advice around things to look out for and steps to take, please visit our IT Services update pages.

Canvas has been safe to use since the incident and no other University systems or data were impacted.