Compromised Accounts
If someone has access to your account, they may not only access your personal information but also Toronto Metropolitan University (TMU) servers. The following steps could help mitigate impact if your account has been compromised.
It’s important to inform the right people of your account breach, even if it’s not yet confirmed.
- Report the incident immediately to help@torontomu.ca and include the following information:
- First and last names
- Employee or student number
- TMU email address
- Non-TMU contact email address
- Contact phone number
- Screen captures/photos showing any settings that have been tampered with
- Report the incident to other system owners that you have access to, such as ServiceHub (Registrar's office) by contacting ServiceHub and using the Human Resources request form.
- Keep a lookout for any suspicious activities on all other systems that you have access to, including any bank accounts associated with the eHR system.
Change your TMU account password immediately.
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Change Password.
Note: If you have any other accounts that share the same password, change these as well.
Change your account recovery.
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Manage Account Recovery option.
Note: You will need to sign up either using your mobile phone (sms) or an email address to recover you password (NOT both).
If you haven’t already, set up two-factor authentication for all applications.
If you had previously set up two-factor authentication, there are two actions to take:
Generate new backup codes for two-factor authentication.
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Two-Factor Authentication.
- Select Show Backup Codes, and select Generate New Backup Codes.
Revoke “trusted” status for all two-factor authenticated devices
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Two-Factor Authentication.
- Scroll to the bottom of the window and select Revoke All Trusted Devices.
Note: Once status is revoked, you’ll need to re-enter two-factor authentication codes the next time you sign in from each device you use for accessing TMU accounts.
If you’ve activated a Google token to access TMU email on your mobile device or email client software, reset the Google token.
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Activate Google Token.
- Select Activate Google Token.
- For details, see our Getting a Google Token page.
Note: Once the Google token is reset, you’ll need to enter the new token on your mobile device or email client software to access TMU email.
There are a variety of settings in your email that can help you determine whether your account has been compromised. Carefully check each of the following.
Tampering method | What Gmail users can do |
---|---|
Deleted content | Check Trash folder for deleted folders and messages. |
Phishing attempts | Check Sent folder for messages that you did not send. |
Delegated sending | Select the gear icon > Settings > under Accounts, check the settings for Send Mail As and Grant Access To Your Account. Verify all information is correct. |
Filters | Select the gear icon > Settings > under Filters and Blocked Addresses, delete anything you do not recognize. |
Email forwarding | Select the gear icon > Settings > under Forwarding and POP/IMAP, delete any forwarding rules you don’t recognize. Learn more about Gmail’s last account activity (external link) information. |
Auto-reply and signature | Select the gear icon > Settings > under General, check your Signature and Vacation Responder settings for any changes you did not make. |
Alternate web sessions | When accessing Gmail via web browser, select the Details link at the bottom of your inbox > select Sign Out All Other Web Sessions. This stops all other computers from continuing to use your account. |
Trusted systems/apps | Review and remove all "apps connected to your account (external link) " |
Redirected sent emails | N/A |
Other hijacked accounts | Check email accounts delegated to you for anything suspicious. |
Check Your Google Drive for Any Suspicious Activity
- Select View Details icon (circle with lowercase letter i on top-right side of window) to view activity log.
- Check for any share privilege changes to folders and documents.
- Check for any suspicious folders and files.
Check Your Recent Security Activity
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under Security, select Recent Security Activity.
Verify Your Personal Information Settings on the my.torontomu Portal
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under General, select Personal Information.
Verify Your Online Resource Settings on the my.torontomu Portal
- Log on to the my.torontomu.ca portal.
- Under the Self Service module, select Personal Account.
- Under General, select Manage My Online Resources.