UMD adds mandatory 2-step authentication for TERPmail users after phishing attack surges 

Adele H. Stamp Student Union at the University of Maryland, College Park, Md. (Sophia Parkins/The Black Explosion)

Nearly 100 University of Maryland TERPmail accounts have been compromised since Aug. 1 following a surge of phishing attacks.

In response to these attacks, the university will require TERPmail users to use 2-step authentication beginning Sept. 21. A system the Division of Information Technology considers necessary to prevent users from further compromises.

More than 185,000 TERPmail users have received at least one phishing scam since Aug. 1, accounting for just about every user, both current students and alumni. However, according to DIT, not all accounts have been compromised as users recognized the problem and changed their passwords before the phisher gained access.

DIT has identified two phishing schemes that target users. One warns users that their account may be deactivated or suspended if they fail to take action and click a link. The second offers unsolicited job opportunities and users must click the link to apply.

Both scams put students and alumni at risk by attempting to steal personal information and account credentials.

“Unfortunately scammers are heavily targeting college students,” said Jeffrey K. Hollingsworth, vice president of information technology and chief information officer for the University of Maryland.

To limit these phishing attacks, the implementation of a mandatory 2-step verification process adds an extra layer of security. This authentication will now require TERPmail accounts to provide a second factor such as access to a security code or phone, in addition to their password.

“2-Step Verification is essentially digital double-locking,” said Hollingsworth. “Just like entry into a campus dorm requires you to swipe your ID card to enter the building, and then you also need your key to unlock the lock to your residence hall room.” 

For some students, the added layer of security is a welcomed measure to prevent further phishing attempts, while others view the additional steps as an inconvenience.

Noah Caro, a sophomore double majoring in immersive media design and information science said he has received a phishing email through his TERPmail account. 

“There was an email, something about a job. I didn’t fall for it, but I knew it was suspicious,” he said.

Despite recognizing the scam, Caro added that while the increased security could make logging into TERPmail inconvenient, he understood its benefits for users who are concerned about privacy.

Adison Traver, a sophomore double majoring in accounting and information systems, said she was disappointed with the institution’s choice to make 2-step authentication a requirement.

“I think it’s dumb. I don’t see why we have to do it. It doesn’t seem any different than what we’re already doing with Duo and how it’s going to fix anything,” she shared.

Traver believes the school officials should be addressing the direct source of the phishing rather than placing additional responsibility on students.

“It shouldn’t be our responsibility to protect our information. It’s the University of Maryland’s responsibility since they’re the ones who have our data and information,” she told The Black Explosion.

The university’s 2-Step authentication deadline is Sept. 21. TERPmail users who do not enroll by the deadline will not automatically lose access to their accounts. Instead, Google will require enrollment the next time they access their email.

Hollingsworth said that although he cannot guarantee that this added measure of precaution will completely eliminate the phishing attacks, “we have seen a significant reduction in the compromise of those accounts” on services already protected by Duo.