Check if there is any malicious email inbox rule

In recent cases of compromised account, some victims reported that their emails were deleted or being forwarded to the hackers. The problem was mostly due to unauthorized email inbox rules set up by the hacker. Please follow the steps below to check whether your mailbox has been injected with such malicious email inbox rules:

HKU staff members

HKU students

For HKU staff members, please proceed with the following steps:
  1. Please login HKU Outlook Web Access (https://hkucc1.hku.hk/owa) with your UID and password (which may be the new password provided by the CF-111 request).
  2. Please click on the Gear button Gear symbol  and select “Options”.
  3. malicious email removal 01
  4. Please choose “organize email” from the left menu and select “Inbox rules”. If you find any rules which are NOT set up by you, please “TICK” the rules and click the “Trash” button to remove them.
  5. malicious email removal 02
  6. Please also check the missing emails from your “Deleted Items” or “RSS Feeds” folder on the left menu. Please move them all from the “Deleted Items” or “RSS Feeds” folder to your Inbox.
For HKU students, please proceed with the following steps:
  1. Please go to https://webmail.hku.hk, click “CONNECT.HKU.HK” and login with your HKU Portal UID and PIN.
  2. Please click the Gear button Gear symbol and select “See all settings”.
  3. malicious email removal 03 student
  4. Click “Filters and Blocked Addresses”. If you find any filtering rules which are NOT set up by you, please “TICK” the rules and click the “Delete” button to remove them.
  5. malicious email removal 04 student
  6. Click “Forwarding and POP/IMAP”. If you find any forwarding rules which are NOT set up by you, please click the radio button next to “Disable forwarding” and click “Save Changes” at the bottom of the page to disable all email forwarding.
  7. malicious email removal 05 student
  8. Remove email forwarding rules which are NOT set up by you by clicking the forwarding email addresses and click “Remove ”.
  9. malicious email removal 06 student
1
3

MFA

Multi-Factor Authentication

February 2024
February 2024

Mandatory for all staff accounts

May 2024
May 2024

Mandatory for all student accounts