California Lutheran University students received an email from an official university address later determined to be an attempted phishing scam earlier this month, according to Information and Technology Services.
The email went out in the early afternoon on Feb. 16 and said the university was undergoing a server renovation. The message said the recipient had numerous logins active on Office 365, Microsoft’s productivity suite.
The email warned that if students did not submit their login information in 24 hours, their MyCLU account would be terminated.
“Our records indicate that your office 365 has two different logins with two different school portals. Kindly indicate the two info logins as soon as possible. To avoid termination of the two school portals within 24 hours, we expect you to strictly adhere to and address them,” the email said. “We will process your termination request shortly. You will lose all your emails associated with this account.”
Upon receiving the email, multiple students posted on Fizz—an anonymous, campus-specific social media platform—with the most popular receiving over 650 “FizzUps,” or likes, expressing concern about the validity of the email, specifically referencing its seemingly internal origin.
Senior Systems Administrator Sean Kreycik said ITS was made aware of the attempted scam when multiple students submitted inquiries about it to the university’s help desk.
“We rely on our community to let us know when they see something that looks suspicious,” Kreycik said. “Any phishing attempt is priority number one every time it comes in, because we know that that can get out of hand real fast.”
The sender of the email was the real address of a former Cal Lutheran student who fell victim to the scam last year, Kreycik said.
In 2025, the scammer contacted the alum directly and requested their password in addition to the accompanying one-time passcode necessary for login, Kreycik said. After gaining the necessary information, the perpetrator logged into the alum’s account. Kreycik said the scammer claimed to be the Cal Lutheran IT help desk, and asked students for passwords and one-time password codes. Four students were compromised over the course of the week, according to Kreycik.
In the recent phishing attempt, students also received a link to a Google Form, which the email claimed could be pasted into the recipients’ browsers to cancel the request.
“Because it came directly from a CLU account, a ‘callutheran.edu’ account, that looks official because it is coming directly from [Cal Lutheran’s] domain,” Kreycik said.
ITS removed the email from students’ inboxes and alerted Google to shut down the fraudulent form, Kreycik said.
Kreycik said that while ITS has specific abilities with Cal Lutheran students’ emails, personal information and specific email messages and conversations are hidden from them by Google.
“Google actually does a really good job at keeping these kinds of things very secret. So we can’t actually go into a student’s email account and view their email,” Kreycik said. “Google doesn’t give us that access.”
Zach Ritter and David Membreno, members of the university’s Computer Science Club, said they were unaware of the phishing email that was sent out, but that a phishing scam from an .edu account was concerning.
“It’s very surprising to me that it was sent out through an .edu email, because usually I feel like that’s the safest option or the safest thing to see,“ Ritter said.
Ritter said students should always exercise an abundance of caution when emails contain links or any other suspicious information to ensure their safety.
“My first piece of advice would just be to look closely at whatever you’re going to open, especially if that’s like a link or if it’s redirecting you to anything,” Ritter said. “Look for correct spelling of company names or even school names, or correct-looking logos.”
Ritter said he’s in favor of the university’s near-sweeping access to students’ emails because it can help protect them when situations like this one arise.
“We’re never going to ask for a password. We’re never going to ask for an OTP code,” Kreycik said. “If anybody’s asking for anything like that, that’s security related, it’s not us.”
