University students panicked after fraudulent emails 'revoked', 'disqualified' degrees

Western Sydney University said the emails are "not legitimate" and have been reported to police.

Large buildings outside. They feature a red shield and white shield with a 'W' in them

Western Sydney University has a number of campuses across Sydney. Credit: Western Sydney University

An Australian university has apologised after reports that some students received emails falsely claiming they had been removed from their courses or had their qualifications revoked.

Current and former students of Western Sydney University (WSU) have posted about the emails on social media this week, with some saying their decades-old degrees had supposedly been revoked.

Other students said they've felt "super stressed" by the incident and will be contacting the university for support.

The university said it "sincerely apologised" for concerns caused.

"Western Sydney University is aware of fraudulent emails sent to students and graduates, with some falsely claiming that they have been excluded from the University or that their qualifications have been revoked," a WSU spokesperson said in a statement to SBS.

"These emails are not legitimate and were not issued by the University."

A second apparent hacking

After the initial flurry of emails sent by a fake address, a second alleged hack took place on Monday night, when a mass email was sent to the WSU community.

This mass email, which came from the university's parking permits account, appears to have been sent by a hacker claiming they exploited the university's cybersecurity.

"This is a glaring indication of the fundamental security weaknesses that still exist within WSU's systems," the email reads.

"What's more concerning is that these vulnerabilities are easily exploited with just a few clicks, and anyone with a basic understanding of web development can access and manipulate sensitive information."

The email claims that WSU has known about the "weakness" in its cybersecurity since 2017, but has "neglected to take meaningful action".
The WSU spokesperson said the university reported the incident to NSW Police.

"As this is part of an ongoing police investigation, we are unable to provide further comment at this time."

One user on Reddit, claiming to have been impacted by the breach, said they had received their degree over a decade ago.

"I received the same email even though I graduated 15 years ago. I guess they don’t purge personal records after 7 years."

Another recipient of the email wrote online about their uncertainty.

"I just had a full-on panic attack and woke up my mum, who read it and pointed out all the reasons why she thinks it's a scam … what do we do about it? Let WSU know or just leave it?"


For the latest from SBS News, download our app and subscribe to our newsletter.

Share
3 min read

Published

By Cameron Carr
Source: SBS News


Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world