The Queen’s IT Services Security team recently became aware of the posting of credentials online that belong to Queen's University account holders. As a precaution, Queen’s IT Services will expire the passwords of any Queen’s account found to be listed on the breached accounts list to ensure that the password posted will no longer be valid.
If you received an email message from IT Services concerning the posting of your credentials, you will be sent additional emails requesting you to change your password, prior to your password expiring. NetID passwords are changed at
https://netid.queensu.ca/selfservice/login/auth
We also encourage you to take the following actions to better protect yourself and your information:
According to reports, email addresses and passwords were posted online.
Queen’s account holders who fail to follow safe password practices are at risk when breaches like this occur. To protect your Queen’s account IT Services are taking this action to prevent account compromises by ensuring all accounts associated with the posting of credentials have refreshed passwords.
It is believed that credentials were obtained from the mining of 3rd party breached data that has been posted online in the past. Account information obtained through other online service breaches are reviewed by hackers and when simple passwords are found, they are tested against other services to see whether the password is still valid with slight variations. IT Services obtain breach information from the service called “Have I Been Pwned?” . Visiting the website https://haveibeenpwned.com/ will allow you to enter and check your Queen’s University email address against all publicized breaches that reference your Queen’s email address. The site also provides details about the data breach, including links to additional information.