March 6, 2026
Fraudulent chat portals vector for ransomware
Denison Security
In February 2026, an unknown threat actor attempted to execute a ransomware attack against a different institution of higher education, located in the United States. The ransomware was delivered through a fraudulent web chat portal.
In a ransomware attack, a piece of malware that encrypts files is used to infect a computer. Once a file is encrypted, it cannot be read from or written to until the encryption is undone. The encryption can only be undone using a key that the threat actor provides, and the threat actor usually tries to extort a ransom in exchange for the decryption key.
Spotting and protecting yourself from ransomware can seem difficult, but there are some basic steps you can take to protect yourself and your data.
- Always back up your data. We recommend the 3-2-1 backup method:
- At least three (3) copies of any important data
- Across at least two (2) storage mediums
- With at least one (1) copy of the data stored off-site.
- Don’t click on suspicious links
- Verify web addresses to make sure they’re what you expect before providing information or downloading software.
- Don’t execute programs or macros that you don’t trust.
For any questions or if you think you may have been affected by ransomware, please reach out to the Service Desk.