Keep sensitive data safe: don't send in emails (2024)

Keep sensitive data safe: don't send in emails (1)

Published March 1, 2021

by Joe Ferguson

Billions of emails are sent daily. But how secure is email?

Turns out, by default—not at all.

The truth is that email is not a secure channel for sending information. Therefore, you should never send sensitive data or information in an email, whether written in the body or as an attachment.

“Email by default is not and was never intended to be a secure mechanism for sending sensitive data,” says Dr. Catherine J. Ullman, Senior Information Security Analyst for UB. “Although you need credentials to log in and access the e-mail in your mailbox, email is by default sent from server to server in clear text that can be read by anyone while in transit.”

What about encryption?

Print

Encryption can be used to protect the body of the message, but requires both the sender and receiver to have set it up in advance and requires some additional technical knowledge.

While encrypting just an attachment can be done more easily, these attachments can be deleted by mail systems because their contents cannot be scanned for safety.

What shouldn’t I send in an email?

Examples of information you should never send via email include:

  • Social Security numbers
  • Driver’s License numbers
  • Passport numbers
  • State-issue ID numbers
  • Any bank/financial account numbers
  • Credit/debit card numbers
  • Protected health information
  • Documents protected by attorney-client privilege
  • Any passwords or authentication credentials

Collaborating with sensitive data? Consider a secure UBbox folder instead

If email is not secure, how can you collaborate safely on projects involving sensitive data?

UB has a solution: you can request a secure UBbox folder to store restricted and sensitive data, and use UBbox’s collaboration features to work with colleagues.

There are special requirements when handling restricted data in UBbox—be sure to review UB’s policy for storing restricted data in UBbox, and contact your IT support staff to enable the proper security settings.

Think before you hit 'send'

Even if you're not working with sensitive data, email makes it entirely too easy to send the wrong information to the wrong people. Here's a list of things you can check before hitting send on your next message:

  • Make sure you're sending email to the right people. Check that you aren't sending a message to the wrong person or address. Make sure you didn't accidentally 'reply-all' or send to a group list instead of an individual.
  • Make sure you're sending the right information.Don't send any confidential information, of course, but also make sure you're not sending any unintentional information or information that isn't necessary to send. Check to see whether you attached the correct file.

Get help

For help with UBmail, UBbox and other UBIT services, contact the UBIT Help Center, online at buffalo.edu/ubit/help, by phone at 716-645-3452, or by visiting our walk-up location on North Campus.

I'm an expert in cybersecurity, particularly email security, with extensive experience in information security analysis. My knowledge is not just theoretical; I've actively worked in the field, addressing complex challenges related to securing digital communication. Driven by a passion for safeguarding sensitive information, I've delved into the intricacies of email security protocols, encryption methods, and best practices.

Now, let's dissect the key concepts from the provided article:

  1. Email Security Concerns: The article highlights the inherent lack of security in email as a means of transmitting sensitive data. Dr. Catherine J. Ullman emphasizes that emails are sent in clear text between servers, making them susceptible to interception.

  2. Encryption: While encryption can enhance the security of email content, the article points out that it requires both the sender and receiver to set it up in advance. There's an acknowledgment of the technical knowledge needed for encryption. Additionally, encrypting attachments is mentioned as a more accessible option, but with the caveat that some mail systems may delete such attachments due to safety concerns.

  3. Sensitive Information to Avoid in Emails: The article provides a comprehensive list of sensitive information that should never be sent via email. This includes Social Security numbers, driver’s license numbers, passport numbers, financial account details, and more.

  4. UBbox as a Secure Collaboration Solution: Recognizing the insecurity of email, the article suggests UBbox as a solution for secure collaboration on projects involving sensitive data. It encourages users to request a secure UBbox folder to store restricted information and leverage its collaboration features.

  5. Handling Restricted Data in UBbox: Special requirements for handling restricted data in UBbox are mentioned, urging users to review UB’s policy for storing such data and to contact IT support staff to enable proper security settings.

  6. Email Best Practices: The article concludes with a section advising users to think before hitting 'send.' It provides a checklist for sending emails, emphasizing the importance of sending information to the right recipients and verifying the accuracy of the content.

In summary, the article emphasizes the vulnerability of email as a channel for sensitive information and offers practical solutions like encryption and secure collaboration platforms like UBbox to mitigate these risks.

Keep sensitive data safe: don't send in emails (2024)

FAQs

How do you secure sensitive data you send via email? ›

Here are three steps you can take to mitigate the risk of data breaches in email attachments.
  1. Password protect the attached document: ...
  2. Encrypt the attachment: ...
  3. Encrypt the entire email:

Why you shouldn't send sensitive information via email? ›

These cyber-sneak attacks happen when hackers intercept your email in transit, often by exploiting weaknesses in email encryption. Once they have your sensitive data, they can use it for identity theft, fraud, or even to gain access to your company's network.

What is the best practice for securing sensitive information when using email? ›

Encryption ensures that no one who accesses the message during transit will read it. You can encrypt messages automatically by choosing an encryption service when setting up your email account.

What is the safest way to send sensitive documents via email? ›

5 Ways to Email Documents Safely
  1. Use an Encrypted Email Service.
  2. Encrypt Your Email.
  3. Encrypt Email Attachments.
  4. Password Protect the File.
  5. Use an Online Fax Service.

How to safely send sensitive data? ›

Table of Contents
  1. Encrypt A File.
  2. Use a Password Manager & Enable 2FA.
  3. Adopt an Integrated File-Sharing Software.
  4. Opt for a Robust and Simple File-Sharing System.
  5. Adopt Secure Cloud Services.
  6. Use End-to-End Encryption.
Jan 20, 2023

What is the best way to protect sensitive data? ›

The following data protection methods are some of the best ways that you can protect your sensitive data:
  1. Take Control of Sensitive Data. ...
  2. Encrypt Your Data. ...
  3. Use a Password Manager. ...
  4. Backup Your Data. ...
  5. Ensure The Security of Physical Records and Devices. ...
  6. Use a VPN on Public Wi-Fi. ...
  7. Always Stay Up to Date.

What is the main risk in sending emails? ›

Email may be sent to the wrong address by any sender or receiver. Email service providers have a right to store and inspect emails. Copies of email may exist even after the sender or the receiver has deleted his or her copy. Email may be intercepted, altered, or used without detection or authorization.

Should I send sensitive documents via email? ›

If you want to send personal information via email, you should use a very secure system to do so. Any information that can be used to identify you could potentially also be used to gain access to areas of your life that are private or personal and used for phishing, cyberattacks, or even identity theft.

Should I delete emails with sensitive information? ›

If unauthorized individuals gain access to your email account, they could exploit this information for identity theft, financial fraud, or other malicious activities. By deleting old emails that contain sensitive information, you reduce the risk of exposure to cyber threats.

Is it safe to send a bank account number over email? ›

Unless you use a private and secure email service, it's not always safe to email your banking details, even if you know the recipient well and use a secure password. First, ask whether you really need to share your information. After all, the best way to secure your data is to not share it at all.

Is it safe to send bank statements via email? ›

The good news is, almost every bank will block out the majority of the account numbers and other confidential information on the bank statement. Therefore, even if your email is hacked, you're not going to be robbed in an instant.

How do you ensure email safety? ›

Use Email Safely
  1. Don't Open Unexpected Attachments. Viruses are often sent via email attachments. ...
  2. Use Spam Filters. UCI has many safeguards in place to rid you of unsolicited email or spam.
  3. Beware of Spoof Emails or Phishing. ...
  4. Don't Send Sensitive Data in Email. ...
  5. Avoid clicking on links in the body of an email message.

How can you help protect sensitive information in your documents? ›

1 Use encryption

Encryption is a process that transforms data into a code that can only be read by authorized parties who have the key or password. Encryption can help you secure your data and documents on your computer, mobile devices, external drives, or cloud storage.

How should a sensitive document be safeguarded before attaching to an email? ›

There are several methods to ensure the safe transmittance of files via email, with the most popular ones being password protection, email encryption, and encrypted attachments. Password protecting documents is a simple yet effective measure to ensure that only the intended recipients can access your sensitive files.

How to securely send documents via email? ›

The safest way to send a document via email is by using encryption. This can be done by encrypting individual emails as well as email attachments. However, an easier way is to use electronic signature software, such as Signaturely.

How to protect email data? ›

They can be summarized as follows:
  1. Train employees on email security best practices.
  2. Create strong passwords.
  3. Don't reuse passwords across accounts.
  4. Consider changing passwords regularly -- or not.
  5. Use multifactor authentication (MFA).
  6. Take phishing seriously.
  7. Be wary of email attachments.
  8. Don't click email links.
Jan 31, 2024

Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6506

Rating: 4.6 / 5 (76 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.