News & Insights

Office of Information Security

Not all cyber threats arrive with flashing warnings or suspicious emails. Some slip in disguised as “helpful” productivity tools - small apps you grab from the Windows Store or download from quick Google searches. These quiet intruders, known as shadow software, are becoming one of the easiest ways attackers enter healthcare environments.

Store Apps: Small Tools, Big Risks

Attackers often package malware inside simple‑looking utilities - screenshot tools, file converters, clipboard managers, PDF editors, or “system boosters.” These apps appear harmless but frequently request far more access than they need. A converter shouldn’t need full file‑system access. A screenshot tool shouldn’t run in the background. Yet many do, quietly interacting with documents, cached sessions, or stored credentials.

Apps that look legitimate can contain abandoned code or hidden components that attackers later exploit.

Web Downloads: Free Isn’t Always Safe

Many “free” utilities downloaded from random websites behave the same way. A PDF editor or converter may look like a quick solution, but some install hidden scripts, send data to unknown servers, or drop extra software you never intended to install. Often, the danger isn’t the document - it’s the tool you used to open or convert it.

Even if an app is free or convenient, it may not be safe to install.

Be cautious if an app:

  • Has vague descriptions
  • Requests full file‑system access
  • Runs in the background
  • Comes from an unknown developer
  • Offers unlimited “free” features

Key Takeaway

Unknown productivity apps may look helpful, but they can potentially do far more than advertised. Once installed, they can open the door for unwanted activity - running hidden tasks, installing extra components, or creating pathways attackers can use later. When a simple tool behaves beyond its purpose, it becomes a security risk instead of a convenience.

Staying Secure

  • Use UTMB‑approved productivity tools
  • Avoid downloading “free” apps from random sites, links, or stores
  • Report anything of suspicion or curiosity to cirt@utmb.edu

A little caution keeps quiet threats from becoming loud problems.

The World Cup brings exciting matches, passionate fans, and unfortunately, many opportunities for cybercriminals. Threat Actors know people are searching for tickets, steaming services, merchandise, and match updates, making the World Cup a prime target for scams.

Threats to Watch For

  • Phishing emails and texts offering “exclusive” tickets, giveaways, or match updates
  • Fake streaming websites promising free access to games
  • Fraudulent merchandise stores selling counterfeit products or stealing payment information
  • World Cup-themed scams designed to trick users into revealing passwords or personal data

How to Stay Safe

  • Enable Multi-Factor Authentication (MFA) on your accounts
  • Verify website URLs before entering login credentials or payment information
    • Make sure you know where the link came from and confirm if the URL matches the official website
  • Only use trusted and authorized streaming platforms
  • Think twice before clicking links in text messages, emails, or social media posts
  • Report any suspicious messages to cirt@utmb.edu

Final Whistle

Just like a championship team relies on a strong defense, good cybersecurity habits keep attackers off the scoreboard. This World Cup season, stay alert, think before you click, and don’t let cybercriminals score a winning goal!

What Is a Login Token?

When you sign in to a Microsoft application with your UTMB email and password and complete multi-factor authentication (DUO Mobile), your device receives a small piece of digital data called a login token. Think of it like a temporary keycard: once it's issued, it lets you move freely between Microsoft services (Outlook, Teams, SharePoint, etc.) without having to login each time. When you select options like "Stay signed in" or "Remember this device," you're telling Microsoft to keep that keycard active for a longer period, allowing your apps to silently confirm your identity in the background so you can work without interruption.

Why Stolen Tokens Are Dangerous

While login tokens are convenient, they're also valuable to attackers—precisely because they bypass the usual security checkpoints. If a threat actor steals a valid login token, they can access your account as if they were you, without ever needing your password or MFA approval. From there, they could:

  • Read and send emails from your account, potentially targeting coworkers or external contacts with convincing phishing messages
  • Access sensitive files in SharePoint, OneDrive, or Teams channels
  • Exfiltrate data such as patient information, internal documents, or financial records
  • Establish persistence by modifying account settings, creating mail-forwarding rules, or registering new devices—making it harder to detect and remove them

Because the attacker is using a legitimate token, this activity can look like normal, authorized use, making it especially difficult to detect.

How Token Theft Can Happen

Attackers may attempt to steal login tokens through:

  • Malicious browser extensions (see our previous Security Corner post!)
  • Phishing attacks designed to capture login credentials or session data
  • Shared or unmanaged devices, such as personal or public computers where tokens may be stored insecurely
  • Malware installed on a device that harvests stored tokens

What's Changing and How It Affects You

Starting at the end of May, we are shortening how long login tokens remain active. A shorter token lifetime means that even if one is stolen, the window in which an attacker can use it is significantly reduced. What this means for you in practice: you may be prompted to enter your username and password, or complete MFA (DUO Mobile) requests more frequently when accessing Microsoft services. We know that adds a small amount of friction to your day, but it meaningfully strengthens the security of your account and our organization. If something doesn't look right, don't hesitate—report it to cirt@utmb.edu.

Some security risks don’t look suspicious. They look helpful.

Browser extensions can add convenience, but they often have more access than most users realize. Many can read and change data across the websites you visit, meaning they can see what you type, view your activity, and interact with your sessions. In the wrong hands, this can expose sensitive information, including access to UTMB systems.

Why This Matters

Because extensions run inside your browser, they can access login pages, email content, and active sessions. A malicious or compromised extension could capture credentials or take actions as you while you are logged in.

In some cases, extensions may be added or modified without a user’s full awareness, especially if a system is compromised or administrative access is misused. This makes it important to periodically review what is installed in your browser.

In a healthcare environment like UTMB, this risk is especially important. Unauthorized access can impact patient data, internal systems, and overall security. Recent examples include fake or malicious extensions, such as AI-related tools, that appeared legitimate but quietly collected user data.

What to Watch For

Be cautious if an extension:

  • Requests access to all websites you visit
  • Comes from an unknown or unverified developer
  • Has little information, few reviews, or a vague purpose
  • Appears installed that you do not recognize or remember adding

If the permissions seem excessive for what it does, that is a strong warning sign.

Safer Habits

Only install extensions you truly need and use trusted developers from official browser stores. Review permissions before installing and avoid extensions that request more access than expected.

Regularly review your installed extensions and remove anything you do not recognize or no longer use. Fewer extensions mean less risk.

Reporting Suspicious Activity

If you notice an unfamiliar extension, unusual browser behavior, or suspect your account may be compromised, report it immediately to UTMB Information Security at cirt@utmb.edu.

Final Thoughts

Browser extensions may seem small, but they can have significant access to your activity. Being selective about what you install and regularly reviewing your browser are simple steps that help protect both your information and UTMB systems.

Cybercriminals are increasingly using Microsoft Teams to trick employees into giving them access to systems, data, or credentials. These scams often look legitimate, and attackers frequently impersonate IT staff or other trusted internal contacts.

How the Scam Works

Attackers may:

  • Send unexpected or suspicious messages in Teams, pretending to be IT, HR, management or a coworker
  • Claim there is an issue or urgent action needed, such as:
    • Account, device, email, or password problems
    • Systems configuration or security issues
    • Fraudulent Teams meeting invites requesting you to review or approve quotes, product orders, delivery schedules, or other business items
  • Pressure you to act quickly, such as "fixing an urgent issue", "verifying your identity", or "preventing account lockout"
  • Ask you to open links, download files, or provide login information through fake "verification" pages or malicious documents
  • Attempt to gain remote control of your computer by asking you to use remote-support tools such as TeamViewer, AnyDesk, LogMeIn, or QuickAssist

Attackers often make their messages look official, using Microsoft branding, real employee names, or files that appear legitimate. These tactics are designed to lower your guard and gain access to sensitive systems.

How to Protect Yourself

  • Be cautious of unsolicited technical help - especially if you didn’t report a problem.
  • Verify the sender through an official channel such as the help desk, ishelp@utmb.edu, a known phone extension, or your manager.
  • Do not start remote sessions using the applications mentioned above unless you opened a support ticket and are expecting assistance.
  • Avoid clicking unexpected links or opening unfamiliar files sent through Teams.
  • Report suspicious Teams messages immediately to the Security Operations Center at cirt@utmb.edu.

Takeaway

Microsoft Teams is a powerful collaboration tool, but scammers increasingly try to misuse it. Always verify unexpected messages or requests, especially those asking for quick action. When something doesn’t look right, report it to cirt@utmb.edu.

Multi-factor authentication (MFA) is one of the most effective tools we have to protect accounts from compromise. However, attackers have adapted their techniques and now focus on exploiting human behavior instead of technical weaknesses. One increasingly common method is known as an MFA fatigue attack.

What Is an MFA Fatigue Attack?

An MFA fatigue attack occurs when a threat actor repeatedly attempts to log in to an account using stolen credentials. Each failed login triggers an MFA prompt such as a push notification, phone call, or approval request sent to the legitimate user.

The attacker’s goal is simple. By sending many prompts in a short period of time, they hope the user will eventually approve one out of frustration, confusion, or distraction. Once approved, the attacker gains access as if they were the authorized user.

Warning Signs to Watch For

You may be experiencing an MFA fatigue attempt if you notice:

  • Multiple MFA prompts you did not initiate
  • Authentication requests arriving back-to-back
  • Login alerts from unfamiliar locations or devices

Any MFA prompt that you did not personally trigger should be treated as suspicious.

What You Should Do

If you receive an unexpected MFA request:

  • Do not approve it
  • Deny the request if possible
  • Change your password immediately
  • Report the activity to CIRT@utmb.edu

Approving a single fraudulent request can allow an attacker to bypass MFA entirely.

Final Thoughts

MFA is a powerful security control, but it relies on users making the right decision at the right time. Treat MFA prompts like a locked door to your account. If you did not request access, do not approve it. Staying alert helps protect both your personal account and the organization as a whole.

AI systems learn from the information you feed them. That means every prompt, file, or snippet of text you submit becomes part of a data exchange—one that may not be as private as you think.

Key risks when handling sensitive data with AI:

  • Unintentional data exposure: Sensitive information—customer records, internal documents, credentials—can be leaked if entered into AI tools that store or reuse prompts.
  • Data retention policies you don’t control: Many AI platforms keep user inputs for training or quality improvement. If you don’t know the retention policy, you can’t guarantee confidentiality.
  • Regulatory non-compliance: Industries governed by HIPAA, FERPA, PCI-DSS, GDPR, or other regulations face legal consequences if protected data is shared with unapproved systems.
  • Shadow IT expansion: Employees using AI tools without oversight create blind spots for security teams.

The rule of thumb is simple: If you wouldn’t email it to an external stranger, don’t paste it into an AI tool.

AI is transforming the way we work, but it must be used responsibly. The combination of sensitive data and unvetted “free” tools can create serious security vulnerabilities. By understanding the risks, establishing strong policies, and choosing secure platforms, UTMB can harness the power of AI without compromising our data.

It’s that time of year again; the tinsel, the lights, the full carts and calendars…

Which means it’s also time for scams. Criminals know the holiday season means stress and distraction, and they know how to take advantage.

AARP’s recent holiday scam reports note that as many as 9-in-10 U.S. adults have encountered at least one scam. Don’t let your money or personal data be a gift to bad actors this season; being familiar with some of the common scams can help you be more vigilant and keep you safe.

Shopping Scams

With retailers advertising deep holiday discounts and competing for our attention, criminals have learned that the way to our wallets is through our eyes. With the rise of AI, it’s never been easier for someone to set up online stores that look like established brands and create realistic advertisements, often distributed via email or social media. By posing as companies customers are familiar with and offering too-good-to-be-true deals, criminals aim to steal money and personal data.

A little vigilance greatly decreases your chance of becoming a victim. When visiting a site linked in an ad, look for the ‘https://’ in the address bar and ensure the address is accurate; if in doubt, look up the company’s proper website address. Typing the address yourself is your safest bet.

When paying, use a credit card and be sure to monitor your transactions for anything suspicious. If something doesn’t look right, dispute the charge.

Gift Card Scams

Gift cards are a gold mine for scammers; their ease-of-use and proliferation during the holidays make them an obvious target. One common scam is criminals posing as a seller listing gift cards as the preferred method of payment. Other classics include fake ‘tech support’ groups requesting gift card numbers and PINs to remediate issues they claim your computer has, and scammers posing as agencies like the IRS or a toll service claiming you owe money that can be repaid via gift card (this will never be legitimate).

One that many companies see is an email or text, pretending to be from an executive or boss, telling the recipient that they need them to purchase some gift cards to help them with an urgent need. They ask the victim to send them the card numbers and PINs, saying they will pay them back soon. The perceived authority and urgency makes a target more likely to comply.

Shipping Issue Scams

Emails and texts pretending to be UPS/USPS/FedEx notifying customers of shipping issues are common throughout the year, and are particularly effective during the holiday season. We want all of our holiday purchases to make it where intended, and seeing an email or text claiming you need to provide personal information or pay a small fee to ‘release a package’ or resolve a shipping issue can cause some panic. Much like with shopping scams, these frequently link to websites dressed (sometimes convincingly) as legitimate carrier services.

Carriers like USPS, UPS, and FedEx generally will not request payment or personal information via unsolicited call, email, or text while goods are in transit. If you are concerned about a package, go to the carrier’s website directly and check your order/delivery status. Never enter your SSN, full DoB, bank info, or card numbers into a page linked in a text.

If something about a holiday message feels urgent, secret, or too good to be true, stop; that sense is a tool, not an accident. When in doubt, take a little extra time to go to a site yourself rather than using links in emails or texts. When paying, use a credit card and monitor your transactions for suspicious activity, disputing anything that doesn’t look right. And finally, if you think your UTMB account or device has been exposed, contact the Office of Information Security right away.

 

Keep your holidays merry and your data safe!


On the twelve days of Christmas, our CISO gave to us…

Day 1. A strong password policy
Use complex, unique passwords.

Day 2. Two-factor protection (Duo)
Add an extra layer of security to your accounts.

Day 3. Three phishing warnings
Watch out for suspicious links and attachments in emails.

Day 4. Four File Safety Fundamentals
Be cautious with downloads, attachments and shared files. Avoid oversharing.

Day 5. Five golden rules

  • Lock your screen
  • Encrypt sensitive data
  • Report incidents promptly
  • Avoid public Wi-Fi
  • Back up your files

Day 6. Six Sneaky Scam Alerts
Be cautious of holiday deals that seem too good to be true.

Day 7. Seven secure connections
Use VPNs when working remotely.

Day 8. Eight SOC analyst
Protecting UTMB resources - 24/7.

Day 9. Nine Necessary Updates
Install critical updates to OS, antivirus and endpoint security tools to keep your devices secure.

Day 10. Ten Trusted Tools
Use only approved, trusted and secure software on your devices.

Day 11. Eleven Security Awareness topics
Visit the Security Corner every month to learn more.

Day 12. Twelve safe practices
Combine all these tips for a secure holiday season!


🎁 Bonus Tip: Cybercriminals love the holidays—don’t give them the gift of your data! Stay vigilant, report suspicious activity, and enjoy a safe festive season.

Collaboration tools like email and SharePoint make teamwork easy, but they also create risks when sensitive information is overshared. Even well‑intentioned actions can expose organizations to insider threats, compliance violations, and reputational damage.

Why Oversharing Matters

Oversharing happens when employees give broader access than necessary—such as using “Anyone with the link” in SharePoint or forwarding confidential email attachments. This can lead to:

  • Data Breaches: Files fall into unintended hands.
  • Regulatory Penalties: Mishandling personal or financial data can trigger fines.
  • Operational Risks: Leaked intellectual property weakens competitive advantage.

Common Scenarios

  • Public SharePoint links overriding security.
  • Email attachments forwarded outside the organization.
  • Shadow IT: personal email or unauthorized tools used for sharing.

The Human Factor

Most incidents stem from good intentions, but convenience must not outweigh security. A culture of awareness—thinking before sharing and following clear guidelines—is essential.

Final Thoughts

Oversharing is a serious insider risk. Strong technical controls plus employee vigilance can prevent leaks and protect valuable information.

Call to Action

Stay Secure. Share Smart. Contact Information Security (security@utmb.edu) or visit the Secure Collaboration Hub for guidance. Report suspicious sharing through the Security Incident Portal.

Narrator:   Ever worry about mixing work and personal data on your phone? With our Microsoft Intune end user device management solution, you don't have to.

When you enroll your device, company apps and data are placed in a secure, separate workspace like a secure virtual briefcase just for work. It keeps business data protected without touching your personal apps, photos, messages, or browsing history. Your privacy stays completely intact.

To keep everything secure, the system checks if your device meets basic requirements like running a supported operating system or having a PIN.  If not, you'll get simple instructions to get back on track.

Why are we doing this? It's an important step in meeting the UT System Information security policy UTS 200, making sure we're all doing our part to keep institutional data safe. It's simple, secure, and helps protect both you and the organization without compromising your personal privacy.

Get more information by visiting byod.utmb.edu.

Narrator

  1. To start your BYOD enrollment, open the Google Play Store, search for the Intune Company portal and tap Install.  
  2. Once the installation is complete, tap Open.  
  3. Allow or Decline company portal notifications.  
  4. These notifications allow Intune to communicate your device status.  
  5. Tap Sign in, then enter your full UTMB email address.  
  6. Tap Next to continue.  
  7. Enter your UTMB password.  
  8. Tap Sign in to continue.  
  9. Approve the duo push.  
  10. Tap Yes, this is my device.  
  11. Tap Begin.  
  12. This screen lays out what controls and information availability apply to your device under BYOD enrollment. 
  13. Tap Continue when ready.  
  14. Tap Accept and continue and wait while Android creates your work profile. 
  15. Tap Next.  
  16. Tap Continue to activate your work profile.  
  17. Select the Personal category.  
  18. Tap Done.  
  19. This screen shows some information about work profile.  
  20. When done reading tap Got It
  21. This screen shows your currently enrolled devices.  
  22. You may now exit the company portal.  
  23. Now when accessing your app library, you will see a Personal and a Work tab.  
  24. Only apps under the Work tab will have access to UTMB resources.  
  25. To install apps in the Work profile, use the Play Store located in the work profile.  
  26. You have now completed the Android enrollment process. 

Narrator

  1. To start your BYOD enrollment, open the Google Play Store, search for the Intune Company portal and tap Install.  
  2. Once the installation is complete, tap Open.  
  3. Allow or Decline company portal notifications.  
  4. These notifications allow Intune to communicate your device status.  
  5. Tap Sign in, then enter your full UTMB email address.  
  6. Tap Next to continue.  
  7. Enter your UTMB password.  
  8. Tap Sign in to continue.  
  9. Approve the duo push.  
  10. Tap Yes, this is my device.  
  11. Tap Begin.  
  12. This screen lays out what controls and information availability apply to your device under BYOD enrollment. 
  13. Tap Continue when ready.  
  14. Tap Accept and continue and wait while Android creates your work profile. 
  15. Tap Next.  
  16. Tap Continue to activate your work profile.  
  17. Select the Personal category.  
  18. Tap Done.  
  19. This screen shows some information about work profile.  
  20. When done reading tap Got It
  21. This screen shows your currently enrolled devices.  
  22. You may now exit the company portal.  
  23. Now when accessing your app library, you will see a Personal and a Work tab.  
  24. Only apps under the Work tab will have access to UTMB resources.  
  25. To install apps in the Work profile, use the Play Store located in the work profile.  
  26. You have now completed the Android enrollment process. 



























Instructions: 

  1. To install an app in your work profile, open the Play Store located in your work profile.   
  2. Select the app you would like to install.   
  3. For this example, select Microsoft Outlook.   
  4. Select the Install button.   
  5. Wait for the app to complete downloading and installing.   
  6. Select Open.   
  7. Some apps may need an account added, if so, select Add account.   
  8. Ensure your UTMB account is selected and select Continue.   
  9. Only UTMB accounts can be added to work apps.   
  10. Select Maybe later.   
  11. Many work apps will give you the option to enable notifications, enable or disable notifications in the installed app by following the permissions prompts.   
  12. You may receive a prompt informing you that UTMB is protecting the app you installed.   
  13. Select Continue when ready.   
  14. Your app is now installed and ready to use. 

Narrator: 

  1. To install an app in your work profile, open the Play Store located in your work profile.  
  2. Tap on the app you would like to install.  
  3. Here we have chosen Outlook.  
  4. Tap the Install button.  
  5. Wait for the app to complete downloading and installing.  
  6. Tap Open.  
  7. Some apps may need an account added.  
  8. Tap Add account.  
  9. Ensure your UTMB account is selected and tap Continue.  
  10. Only UTMB accounts can be added to work apps.  
  11. Tap Maybe later.  
  12. Many work apps will give you the option to enable notifications, enable or disable notifications in the installed app by following the permissions prompts.  
  13. You may receive a prompt informing you that UTMB is protecting the app you installed.  
  14. Press Continue when ready.  
  15. Your app is now installed and ready to use. 

Narrator:

  1. To install an app for work, tap the UTMB company portal icon that was added to your device during BYOD enrollment.
  2. If prompted, choose your UTMB account.
  3. Choose the type of device you are currently using.
  4. Select the app you want to install. In this case we are installing the Outlook email app.
  5. You may need to select your device if this message is displayed, tap on the message to confirm your device, then select the device you are currently using.
  6. Once you've selected your device, tap the Install button.
  7. Tapping the Install button will send a request to Intune to push the app to your device.
  8. This may take a few minutes.
  9. When prompted, press the Install button.
  10. Wait for the app to complete installing, then tap on the app to open it.
  11. Depending on the app you install, you may be prompted to add an account.
  12. You may receive prompts indicating that UTMB is protecting data in the app.
  13. Please accept and follow the instructions in these prompts.
  14. After accepting these prompts, you may be asked about permissions for the app.
  15. Once permissions have been chosen, the app installation is complete.

[Background music]

Narrator:

Here at UTMB, we take information security seriously. Whether it's patient information, financial documents, or private employee information, it's an ongoing effort to keep that data safe. This video will be covering the Intune enrollment process for iPhones.

To get started, we need to make sure that a few Microsoft apps are not on your phone. We will be removing Authenticator, Teams, and Outlook. If these apps are not on your phone, feel free to skip ahead to the next part of the video. You may also uninstall any other Microsoft programs that you may need.

Here, we'll be demonstrating the process to remove an app, using Authenticator as an example.

  1. First, we're going to swipe from right to left until we reach the App Library. This library contains every app installed on your phone.
  2. Next, we're going to select and hold the Authenticator app, then select Delete App from the menu that appears and confirm by selecting Delete again.
  3. While you're here in the App Library, you can search for both the Teams and Outlook apps and delete them using the same method.

Next, be sure to turn off your Wi-Fi if you're physically located at a UTMB facility. If you're at home, you can continue without making any changes.

  1. Now we're going to open the Settings menu, represented by a gear icon.
  2. In the Settings, open the General section of the Settings menu.
  3. Next, select VPN & Device Management. Now we're in the correct menu to begin the enrollment.
  4. Select Sign in with Work or School Account. This will bring up a text box where you can enter in your UTMB email address, then select Continue.
  5. After submitting your password, a Duo screen will appear, followed by a Duo notification at the top of your screen.
  6. You can swipe down on the Duo notification to approve it.
  7. It is important that you do not leave this screen, as it can reset the enrollment process back to the beginning.
  8. Now that you've processed the Duo push, a new screen will appear asking, Is this your device?
  9. Select Yes, this is my device.
  10. A prompt will now appear where you will sign into iCloud by selecting the option at the bottom, labeled Sign into iCloud.
  11. Now the screen will say, Apple account for your organization.
  12. Select Continue to proceed.
  13. After submitting your password, a Duo screen will appear, followed by a Duo notification at the top of your screen.
  14. You can swipe down on the Duo notification to approve it. You will be given the option to stay signed in.
  15. Select No to avoid future lockouts when your password is changed.
  16. Select Allow Remote Management and then enter your six-digit iPhone PIN. If your PIN is still 4 digits, you'll be asked to change to a six-digit PIN when adding your Intune apps. The process of changing your PIN and adding Intune apps to your phone is shown in a separate video in the BYOD series.
  17. You will now get a prompt notifying you about the initial Intune app installation.
  18. Select Install, and your phone will install UTMB Company Portal, Microsoft Authenticator, Microsoft Outlook, and Microsoft Teams.
  19. This app installation can take up to 30 minutes, so you may not have access to the apps immediately.

Once your apps are installed, open the Microsoft Teams app.

  1. When the app opens, you will be prompted to select an account.
  2. Select your UTMB account to continue. You will then see a prompt indicating that the app will restart.
  3. Select OK. Teams will ask for location permissions.
  4. Select Allow while using app.
  5. Finally, Teams will ask for notification permissions.
  6. Select Allow to receive alerts for any messages or calls that you will be receiving from Teams.

That's it. You're officially enrolled in Intune!

If you experienced any errors or problems during this process, please check out the troubleshooting section of the BYOD instructional page at byod.utmb.edu.