Campus News

Security Alert: Active email phishing attack underway

Please remain vigilant and report any suspicious emails immediately.

By

Dear Campus Community,

UC Santa Cruz is currently experiencing an ongoing email phishing attack. While Information Technology Services (ITS) is actively blocking these attempts and working to contain the impact, some users have already been affected. Please remain vigilant and report any suspicious emails immediately.

How this most recent phishing attack works

Attackers send emails from compromised university email addresses with official-sounding subject lines. These emails contain links that redirect to fake login pages designed to steal your credentials and capitalize on the “remember my device” functionality in Duo multi-factor authentication. Learn more about these attacks: Security Alert: Email phishing targeting UC Santa Cruz.

If we detected that your account may have been compromised, we have proactively reset it to protect your information and university resources. To regain access, please follow the steps below to re-establish your account credentials and sign back in:

Why this attack is particularly dangerous

  • Users see legitimate UCSC Duo prompts and unknowingly approve them
  • Attackers gain full access to email, UCPath, and other sensitive systems and information
  • “Remember my device” settings allow ongoing access without re-authentication
  • Compromised accounts are used to launch additional attacks

How to protect yourself

  • Verify sender authenticity before clicking any links
  • If you weren’t actively logging in when you received a Duo push, don’t approve it
  • Navigate directly to UCSC sites rather than clicking email links
  • Report suspicious emails immediately

Learn more and get support

  • Forward suspicious emails to phishing@ucsc.edu, which alerts both the Information Security team and the ITS Service Desk, ensuring coordinated and timely response
  • If you believe you are a victim of a phishing attempt, contact the ITS Service Desk

Refresh your cybersecurity knowledge: Cybersecurity for Employeesand Cybersecurity for Students

Related Topics

Last modified: Jun 11, 2026