Dr Fadi Aloul hopes to present the research at a cyber security seminar.
Dr Fadi Aloul hopes to present the research at a cyber security seminar.
Dr Fadi Aloul hopes to present the research at a cyber security seminar.
Dr Fadi Aloul hopes to present the research at a cyber security seminar.

Phishing ruse nets 1,000 at university


  • English
  • Arabic

ABU DHABI // The e-mails seemed innocuous enough. One was a routine message requesting a university account password change. The other promised entry into a prize raffle in return for filling out a banking survey.

But both were fraudulent. Fortunately, for many unsuspecting recipients at the American University of Sharjah (AUS) who followed the hackers' instructions, they were part of a harmless ruse, an experiment to see how many people would fall victim to a phishing scam. The first part of the university-sanctioned experiment, conducted in April on 10,000 students, alumni, staff and faculty, lured 954 people into trying to change their university log-on passwords. More than 200 students fell for the second part, which involved them saying what banks they used.

No names or personal information were recorded during the experiment. More than 96 per cent of those fooled were current students, said Dr Fadi Aloul, an associate professor in computer engineering, who supervised the study. "I was definitely surprised to see such a large number in terms of students," he added. Phishing attacks use spoof e-mails and bogus websites to trick recipients into sharing sensitive data. "Almost on a monthly basis, we get regular e-mails from bank-phishing e-mail addresses saying: 'Your AUS account has been locked', which is a typical rip-off," Dr Aloul said.

Cyber attacks in the Middle East had boomed in recent years, according to the computer security firm Trend Micro. "It's still viewed as a rich region with an opportunity for a more recipient and less aware market when it comes to these threats," said Ian Cochrane, the company's marketing manager in Dubai. Although AUS's IT department routinely warns its web community members to be vigilant, Dr Aloul suspected that the alerts went ignored. It appears that, in many cases, he was right, despite the IT department sending out a warning about the fake attack.

"It tells you that students don't care much about reading these e-mails carefully," Dr Aloul said. "After seeing this experiment, I hope it made a better impact on them." Amna, 21, who is majoring in computer engineering at AUS, was one of the students caught out. "The point is that it made me more aware," she said. "Seeing it happen and then when I saw the e-mail from an IT director, that just made me realise it does happen. We see e-mails and we read them, but it doesn't hit us until it actually takes place.

"I was actually happy that someone made me realise. It would have been much worse if it had been a real attempt. I was lucky because the first time it happened to me, nothing bad happened. People probably lose a lot of money on things like that. "It was a nice way to make people aware. It's a fun experiment to be a part of, rather than as a victim." The idea for the experiment came from a conversation with the university's IT director. "They're doing a good job sending the e-mail warnings, but I asked him if he knew how many people actually fell for this?" Dr Aloul said. "He didn't know, so I proposed, let's be the hackers for one day and make it in a controlled way."

The only other people aware of the test were the university's provost and three computer engineering students, Jamshaid Mohebzada, Arsalan Bhojani, and Ahmed El Zarka, who created the phoney e-mails. The first went out on April 10, urging recipients to change their passwords "immediately", after a "security intrusion". The link displayed in the e-mail redirected people to a strange domain name that was not associated with the university.

"Unfortunately, many people don't check the URL [uniform resource locator, the global address of documents and other resources on the internet], so people went to that page and sent their usernames," Dr Aloul said. The second e-mail was sent 10 days later, requesting names, phone numbers, e-mail addresses and asking which bank recipients used. It offered a computer flash drive as a prize for taking part in the survey.

While 220 students fell for it, the 350 staff and faculty members appeared to have learned their lesson. "Staff and faculty did not bother at all, it was zero," Dr Aloul said. Dr Aloul hopes to present the research at a future cyber security seminar and is trying to have the study published in an academic journal. mkwong@thenational.ae

EA Sports FC 26

Publisher: EA Sports

Consoles: PC, PlayStation 4/5, Xbox Series X/S

Rating: 3/5

Sly%20Cooper%20and%20the%20Thievius%20Raccoonus
%3Cp%3E%3Cstrong%3EDeveloper%3A%3C%2Fstrong%3E%20Sucker%20Punch%20Productions%3Cbr%3E%3Cstrong%3EPublisher%3A%3C%2Fstrong%3E%20Sony%20Computer%20Entertainment%3Cbr%3E%3Cstrong%3EConsole%3A%3C%2Fstrong%3E%20PlayStation%202%20to%205%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%205%2F5%3C%2Fp%3E%0A
TICKETS

Tickets start at Dh100 for adults, while children can enter free on the opening day. For more information, visit www.mubadalawtc.com.

Crime%20Wave
%3Cp%3EHeavyweight%20boxer%20Fury%20revealed%20on%20Sunday%20his%20cousin%20had%20been%20%E2%80%9Cstabbed%20in%20the%20neck%E2%80%9D%20and%20called%20on%20the%20courts%20to%20address%20the%20wave%20of%20more%20sentencing%20of%20offenders.%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3ERico%20Burton%2C%2031%2C%20was%20found%20with%20stab%20wounds%20at%20around%203am%20on%20Sunday%20in%20Goose%20Green%2C%20Altrincham%20and%20subsequently%20died%20of%20his%20injuries.%3C%2Fp%3E%0A%3Cp%3E%26nbsp%3B%E2%80%9CMy%20cousin%20was%20murdered%20last%20night%2C%20stabbed%20in%20the%20neck%20this%20is%20becoming%20ridiculous%20%E2%80%A6%20idiots%20carry%20knives.%20This%20needs%20to%20stop%2C%E2%80%9D%0D%20Fury%20said.%20%E2%80%9CAsap%2C%20UK%20government%20needs%20to%20bring%20higher%20sentencing%20for%20knife%20crime%2C%20it%E2%80%99s%20a%20pandemic%20%26amp%3B%20you%20don%E2%80%99t%20know%20how%20bad%20it%20is%20until%20%5Bit%E2%80%99s%5D%201%20of%20your%20own!%3C%2Fp%3E%0A
AndhaDhun

Director: Sriram Raghavan

Producer: Matchbox Pictures, Viacom18

Cast: Ayushmann Khurrana, Tabu, Radhika Apte, Anil Dhawan

Rating: 3.5/5

Brief scoreline:

Wales 1

James 5'

Slovakia 0

Man of the Match: Dan James (Wales)

Who's who in Yemen conflict

Houthis: Iran-backed rebels who occupy Sanaa and run unrecognised government

Yemeni government: Exiled government in Aden led by eight-member Presidential Leadership Council

Southern Transitional Council: Faction in Yemeni government that seeks autonomy for the south

Habrish 'rebels': Tribal-backed forces feuding with STC over control of oil in government territory

Biog

Mr Kandhari is legally authorised to conduct marriages in the gurdwara

He has officiated weddings of Sikhs and people of different faiths from Malaysia, Sri Lanka, Russia, the US and Canada

Father of two sons, grandfather of six

Plays golf once a week

Enjoys trying new holiday destinations with his wife and family

Walks for an hour every morning

Completed a Bachelor of Commerce degree in Loyola College, Chennai, India

2019 is a milestone because he completes 50 years in business

 

Mercer, the investment consulting arm of US services company Marsh & McLennan, expects its wealth division to at least double its assets under management (AUM) in the Middle East as wealth in the region continues to grow despite economic headwinds, a company official said.

Mercer Wealth, which globally has $160 billion in AUM, plans to boost its AUM in the region to $2-$3bn in the next 2-3 years from the present $1bn, said Yasir AbuShaban, a Dubai-based principal with Mercer Wealth.

Within the next two to three years, we are looking at reaching $2 to $3 billion as a conservative estimate and we do see an opportunity to do so,” said Mr AbuShaban.

Mercer does not directly make investments, but allocates clients’ money they have discretion to, to professional asset managers. They also provide advice to clients.

“We have buying power. We can negotiate on their (client’s) behalf with asset managers to provide them lower fees than they otherwise would have to get on their own,” he added.

Mercer Wealth’s clients include sovereign wealth funds, family offices, and insurance companies among others.

From its office in Dubai, Mercer also looks after Africa, India and Turkey, where they also see opportunity for growth.

Wealth creation in Middle East and Africa (MEA) grew 8.5 per cent to $8.1 trillion last year from $7.5tn in 2015, higher than last year’s global average of 6 per cent and the second-highest growth in a region after Asia-Pacific which grew 9.9 per cent, according to consultancy Boston Consulting Group (BCG). In the region, where wealth grew just 1.9 per cent in 2015 compared with 2014, a pickup in oil prices has helped in wealth generation.

BCG is forecasting MEA wealth will rise to $12tn by 2021, growing at an annual average of 8 per cent.

Drivers of wealth generation in the region will be split evenly between new wealth creation and growth of performance of existing assets, according to BCG.

Another general trend in the region is clients’ looking for a comprehensive approach to investing, according to Mr AbuShaban.

“Institutional investors or some of the families are seeing a slowdown in the available capital they have to invest and in that sense they are looking at optimizing the way they manage their portfolios and making sure they are not investing haphazardly and different parts of their investment are working together,” said Mr AbuShaban.

Some clients also have a higher appetite for risk, given the low interest-rate environment that does not provide enough yield for some institutional investors. These clients are keen to invest in illiquid assets, such as private equity and infrastructure.

“What we have seen is a desire for higher returns in what has been a low-return environment specifically in various fixed income or bonds,” he said.

“In this environment, we have seen a de facto increase in the risk that clients are taking in things like illiquid investments, private equity investments, infrastructure and private debt, those kind of investments were higher illiquidity results in incrementally higher returns.”

The Abu Dhabi Investment Authority, one of the largest sovereign wealth funds, said in its 2016 report that has gradually increased its exposure in direct private equity and private credit transactions, mainly in Asian markets and especially in China and India. The authority’s private equity department focused on structured equities owing to “their defensive characteristics.”

The Dark Blue Winter Overcoat & Other Stories From the North
Edited and Introduced by Sjón and Ted Hodgkinson
Pushkin Press 

MATCH INFO

First Test at Barbados
West Indies won by 381 runs

Second Test at Antigua
West Indies won by 10 wickets

Third Test at St Lucia
February 9-13

 

Milestones on the road to union

1970

October 26: Bahrain withdraws from a proposal to create a federation of nine with the seven Trucial States and Qatar. 

December: Ahmed Al Suwaidi visits New York to discuss potential UN membership.

1971

March 1:  Alex Douglas Hume, Conservative foreign secretary confirms that Britain will leave the Gulf and “strongly supports” the creation of a Union of Arab Emirates.

July 12: Historic meeting at which Sheikh Zayed and Sheikh Rashid make a binding agreement to create what will become the UAE.

July 18: It is announced that the UAE will be formed from six emirates, with a proposed constitution signed. RAK is not yet part of the agreement.

August 6:  The fifth anniversary of Sheikh Zayed becoming Ruler of Abu Dhabi, with official celebrations deferred until later in the year.

August 15: Bahrain becomes independent.

September 3: Qatar becomes independent.

November 23-25: Meeting with Sheikh Zayed and Sheikh Rashid and senior British officials to fix December 2 as date of creation of the UAE.

November 29:  At 5.30pm Iranian forces seize the Greater and Lesser Tunbs by force.

November 30: Despite  a power sharing agreement, Tehran takes full control of Abu Musa. 

November 31: UK officials visit all six participating Emirates to formally end the Trucial States treaties

December 2: 11am, Dubai. New Supreme Council formally elects Sheikh Zayed as President. Treaty of Friendship signed with the UK. 11.30am. Flag raising ceremony at Union House and Al Manhal Palace in Abu Dhabi witnessed by Sheikh Khalifa, then Crown Prince of Abu Dhabi.

December 6: Arab League formally admits the UAE. The first British Ambassador presents his credentials to Sheikh Zayed.

December 9: UAE joins the United Nations.

The specs: 2019 Lincoln MKC

Price, base / as tested: Dh169,995 / Dh192,045

Engine: Turbocharged, 2.0-litre, in-line four-cylinder

Transmission: Six-speed automatic

Power: 253hp @ 5,500rpm

Torque: 389Nm @ 2,500rpm

Fuel economy, combined: 10.7L / 100km

UAE squad

Humaira Tasneem (c), Chamani Senevirathne (vc), Subha Srinivasan, NIsha Ali, Udeni Kuruppuarachchi, Chaya Mughal, Roopa Nagraj, Esha Oza, Ishani Senevirathne, Heena Hotchandani, Keveesha Kumari, Judith Cleetus, Chavi Bhatt, Namita D’Souza.

RESULTS

5pm: Watha Stallions Cup Handicap (PA) Dh 70,000 (Dirt) 2,000m

Winner: Dalil De Carrere, Bernardo Pinheiro (jockey), Mohamed Daggash (trainer)

5.30pm: Maiden (TB) Dh 70,000 (D) 2,000m

Winner: Miracle Maker, Xavier Ziani, Salem bin Ghadayer

6pm: Maiden (PA) Dh 70,000 (D) 1,600m

Winner: Pharitz Al Denari, Bernardo Pinheiro, Mahmood Hussain

6.30pm: Maiden (PA) Dh 70,000 (D) 1,600m

Winner: Oss, Jesus Rosales, Abdallah Al Hammadi

7pm: Handicap (PA) Dh 70,000 (D) 1,400m

Winner: ES Nahawand, Fernando Jara, Mohamed Daggash

7.30pm: Maiden (PA) Dh 70,000 (D) 1,000m

Winner: AF Almajhaz, Abdul Aziz Al Balushi, Khalifa Al Neyadi

8pm: Maiden (PA) Dh 70,000 (D) 1,000m

Winner: AF Lewaa, Bernardo Pinheiro, Qaiss Aboud.

How Beautiful this world is!