Security to go

Security to go - Newsletter

The Information and Data Security Unit would like to provide all members of the University of Bonn with short insights into the world of IT and data security at regular intervals. With this, we want to draw attention to risks and developments, raise awareness of cyber threats, and give you simple measures you can take. 

We would be delighted if you would subscribe to our newsletter!

August 2026 - Delayed Spring Cleaning

A desktop showing way too many Word and PDF documents, a Downloads folder filled with forms and information from the web—does that sound familiar?

When it comes to our PCs, many of us quickly turn into collectors of old files. Sometimes we have forgotten about them as we only needed them briefly; sometimes we keep them “in case they come in handy again in the future.” 

We should bear in mind, however, that deleting old files regularly not only enhances system performance, but also keeps us from violating any GDPR provisions or posing security risks, depending what kind of data we are looking at. Personal data may only be stored as long as is required for the respective purpose; they must be deleted subsequently, provided no statutory storage requirements apply. This applies to all devices and accounts, i.e. including your work phone and sciebo account. 

Hence today we would like to invite you to do a spring-clean—it is never too late

Would like to start right away, but are not sure where?  Here are some ideas: 

  • Have you held any job interviews in the past and maybe have not deleted all applications yet? Now would be the perfect time to do so.
  • Do you take pictures of documents or interesting information from time to time? Start in the gallery of your smartphone.
  • Are you involved in teaching and have made notes on students whose work has been assessed by now? In that case, you surely will not need these notes any longer. Do you have a list of grades that have already been transferred to HisInOne in the meantime? This list then has become superfluous too.
  • Using the Downloads folder and desktop for storing temporary files is common. If that sounds like you, we recommend starting there.

Tips to keep your laptop clean and tidy: 

  • Only use sample personal data when creating templates for important documents; please never save templates using real personal data.
  • Creating a folder for documents that are only needed for a short time and emptying it on a regular basis may keep you from collecting too many files in the first place. This approach may serve equally well for emails in your inbox.
  • Always store documents directly in the designated folders instead of letting them sit endlessly in your Downloads folder.

If you would like to find out more about how personal data should be handled, we recommend checking the overview provided here [external link, available in German only]. Go to Service Portal for information on privacy and data protection at the University.

Exampleofdigitalhoarding_cluttereddesktop001.webp
© Wikissed

Past Issues

Anyone with an email address will be used to receiving messages about a hitherto unknown but suddenly deceased uncle who has left them a fortune or from a foreign prince asking for help hiding his wealth. Whereas most people will by now recognize these kinds of email as spam, our inboxes are increasingly being flooded with messages that—thanks not least to AI—give the appearance of being from our own bank or employer.

Phishing emails remain one of the most common kinds of cyberattack and, even with good filters, a few will still make it as far as your inbox rather than automatically ending up in your spam folder. According to the German Federal Office for Information Security (BSI), one in three unsolicited emails is a phishing attempt.

What exactly is phishing?

Phishing is any fraudulent attempt to obtain sensitive information such as passwords, login details or credit card numbers by faking some element of the communication process. The fraudsters pose as trustworthy senders, such as your bank, your line manager or a familiar service provider, in order to trick you into clicking on links, entering your details or opening attachments.

Different kinds of unsolicited email

Although not every unsolicited email is equally dangerous, many spamming/phishing attempts follow set patterns that you should be able to recognize. People at the University encounter the following examples all the time:

The assertion that your account is about to expire or you have exceeded your storage allowance

You are prompted to log in to prevent this—and are often given very little time to do so. Clicking on the links will take you to fake web pages that look so similar to the genuine login page as to be indistinguishable. If you get an email like this, please report it to sicherheitsteam@uni-bonn.de.

You can rest assured that the University will never send emails asking you to extend or renew any accounts. Only if your Uni-ID is due to expire (e.g. because your work contract is coming to an end) will you be notified—and this well in advance.

“Are you in the office?”/“Please get in touch, there’s something I’d like to ask you about in confidence”

Staff are always getting emails claiming to be from their line manager or other important people at the University asking them to get in touch with them discreetly. These emails are often sent from commercial email providers such as Gmail. Anyone replying to an email like this will often be asked to buy cash cards and email the codes to their “line manager.” These requests are often accompanied by an emotional backstory or attempt at manipulation; for example, the recipient is put under pressure for something to be done quickly or threatened with reprisals if they fail to act.

You must not reply to emails like these. Instead, report them to sicherheitsteam@uni-bonn.de. 

If you are a line manager yourself, please explain to your staff what communication channels you will use for what purposes. You should also encourage your team to contact you if they receive unusual inquiries via a different method (e.g. over the phone).

CEO fraud

This is similar to the scam described above and involves an attempt to engineer a large payment via a non-standard method, generally on behalf or in the name of University management.

Emails from your own account

People sometimes get an email that appears to have been sent from their own address. There will usually be some technical tricks in play here, meaning that the email did not really come from your own account. To be on the safe side, please notify sicherheitsteam@uni-bonn.de.

Gifts and offers for sale from colleagues

We have recently seen an increase in the number of emails that appear to have come from an associate of the University and that talk about a normally expensive product being given away for free (e.g. welding equipment or musical instruments). Please check first of all whether the sender’s email address matches their name and belongs to the University’s own domain. Call the person if needed to make sure that their offer is genuine. To be on the safe side, please notify sicherheitsteam@uni-bonn.de nonetheless.

Invitations from academic or scientific journals

Many researchers are often invited to contribute their work to journals or conferences (some of which will be more reputable than others). If you do not wish to receive these emails, you can block the senders yourself in your email settings.

Important information

Phishing attempts are becoming increasingly personalized, thanks not least to AI. The more information fraudsters have about you (social media, public profiles), the more convincing their messages will come across as.

Even experienced users can be fooled. It is not essential to be perfect. Instead:

  • Report suspicious messages quickly (even if you did not act on them) to protect other people from them.
  • Change your password immediately if you have entered your details anywhere.
  • Be suspicious of any unexpected requests rather than taking them at face value.

And it is not just via email that fraudsters will try and steal your money or your data—you should also watch out for text messages, phone calls and QR codes.

Checklist for suspicious emails

  • Check the sender’s address carefully (it will often be slightly altered or from a commercial provider like Gmail).
  • You should scrutinize the backstory in the email, especially if it is attempting to put you under time pressure or uses highly emotional language. If you are in any doubt, you should contact the person who appears to have sent it, using a different method.
  • Do not click on any links. Instead, go to the website by typing the address into your browser yourself.
  • Never disclose any passwords, bank details or the like.
  • Forward any suspicious emails to sicherheitsteam@uni-bonn.de 

Incidentally, if you have always wondered what really happens when you click on obvious spam emails, we recommend watching this TED talk (on YouTube). Please don’t try this at home (at least not with your current email address)!

As the EU country that sees the most cyberattacks, Germany is at constant risk of both internal and external threats—and universities, with the wealth of data they hold on students, their promising fields of research and their links to business and industry, are a particularly lucrative target for such attacks. These often focus on the accounts of staff and students in order to steal data or mount further attacks.

This is because nearly everything we do online these days, from writing emails to working on systems, starts with a login into an account, generally with a username and password. The problem is that, as soon as someone else knows this combination (e.g. through phishing, a data leak or simple trial and error), they will be able to log into your accounts just as you would. This will give them access to all the information stored there and the ability to view, modify or delete it while acting in your name. Thus they will have stolen your digital identity.

So what can we do to protect our accounts more effectively?

Multifactor authentication (abbreviated as “MFA” or “2FA” and sometimes called “strong authentication”) uses an additional element to secure your account. To log in, you will usually need a combination of 

  • something you "know” (the knowledge factor, such as a password or PIN);
  • something you “have” (the possession factor, such as a smartphone, USB stick or bank card); and
  • something you “are” (the inherence factor, such as a fingerprint or face shape).

This means that, although you need more than your username and password to log in, a criminal would also need access to that second factor in order to do so, which will not normally be the case.

You will already have seen the concept at work at ATMs, where you enter your card (possession) together with your PIN (knowledge) as a matter of course so that you can withdraw cash.

This bird provides a visual explanation of why a second factor adds protection (external link). 

Use at the University:

The University of Bonn is also introducing MFA. In a project, all staff were issued with a physical factor (a Yubikey), i.e. something that you will “have.” This solution is capable of warding off third-party attacks in many cases and will make it much harder for hackers to get at your user account.

The extra effort required to use a second factor will be barely noticeable but will significantly improve the security of your logins as well as IT and data security across the whole University.

Tips for advanced users: 

Your email account in particular should be especially well protected, because people can often reset their passwords (and sometimes even their second factor) by email.
Think about which of your accounts contain critical data or are important to you for whatever reason. Now tackle one of these accounts every day and give it an added layer of security.
Many websites try to make sure that you can continue to access your account even if you mislay your second factor, e.g. by supplying backup codes. If you are given these, you should store them in a safe place, such as electronically in password managers (e.g. KeePassXC) or physically in a locked cabinet or safe deposit box.

Links for more information: 

HRZ Information on MFA
BSI Information on MFA (external link)
Microsoft Defense Report 2025 (external link)


Topic suggestions, feedback, or praise?

Is there a topic you would like us to cover in one of our upcoming editions, or would you like to let us know how you have enjoyed the content so far? We would love to hear from you.

Whether it’s a specific suggestion, constructive feedback, or just a few kind words, your input helps us make the newsletter even more useful and engaging.

Feel free to send us an email!


Wird geladen