Skip to content
Allegheny students affected by scam emails

Allegheny students affected by scam emails

Alleghenycampus September 4, 2026

While campus was quiet over the summer, cyber scammers stayed busy, sending Allegheny students phishing emails designed to trick recipients into clicking links or sharing information, disguised as “party invitations” and documents to sign.

Cyber “phishing” is an attempt to trick users into opening a document, clicking on a link or providing private information by posing as a trusted source.

The phishing email compromised a “handful” of individual student email accounts after students clicked on links in the emails that appeared to come from other students or familiar Allegheny contacts, according to Katrina Yeung, Allegheny’s chief information officer.

Allegheny uses a layered cybersecurity model, with Google controls and other security measures in place to detect and respond to suspicious activity. According to Yeung, the system is designed to provide multiple levels of protection if one security measure fails. It was through those security measures that the college was able to detect the unusual activity during the summer. The campaign began when a student clicked on a link, compromising the student’s email account. The compromised account then sent similar phishing emails to other Allegheny accounts.

“We noticed that a mass amount of emails were being sent,” Yeung said. “Passwords were quickly locked down and changed.” A campus-wide email was sent to raise awareness the phishing attempts.

The attempts targeting Allegheny used several different types of emails, including “party invitations and requests to sign documents through DocuSign,” Yeung said. She added that the emails could appear legitimate, making it important for students to verify any unexpected emails before responding to them.

Grace Moon, ’28, stated that she received at least two false party invitations over the summer, appearing to come from other student’s compromised accounts. Moon said she was suspicious after receiving multiple invitations and later noticed that one of the emails had disappeared from her inbox. Moon mentioned she had initially kept the email thinking “maybe I should keep this one here, and then it evaporated.”

Moon had also been checking her Allegheny email more frequently over the summer because she had been applying to study abroad programs. A similar message during the school year might have seemed more believable because students regularly receive emails housing, organization work and other college-related matters. “If it happened during the school year, I probably would have been like, oh yeah, this makes sense,” Moon said. “I need to sign something for, I don’t know, the Outing Club board, or my housing paperwork, who knows?”

Katelyn Ebbert, ’29, received an email she believed to be from a student she worked with in an organization on campus. The email asked her to review and sign a document and initially it appeared legitimate to Ebbert because she had been in with the student recently.The request to sign a document did not immediately seem suspicious to her. “Of course I have a document to sign,” Ebbert recalled thinking.

The phishing attempts also raised concerns among students the security of their Allegheny accounts. Moon mentioned that she had experience with scams in the past. “I have worked in public libraries and I’ve done anti-scam training,” Moon said. “Even with the warnings and the training, it’s so hard sometimes to tell because sometimes it says @allegheny.edu, and then @gmail comes after it, and you don’t look twice. Or if it’s coming from somebody who you know, it’s hard to tell.”

The college found no evidence that other campus systems or student data were accessed according to Young. The incident remained limited to individual email accounts. “We see no evidence of bad actors in any systems,” Yeung said.

Yeung explained that scammers often rely on information that can make an email seem familiar or trustworthy. She encouraged students to pay attention to who they are communicating with and to verify unexpected requests through another form of communication before responding. “When in doubt, really stop,” Yeung said. “Don’t click.”

Anas Adnan, ’29, had a different experience. He has received scam emails twice, including one during the summer before his first year and another this summer. Both emails appeared to use the name of an Allegheny professor and offered him a paid research opportunity.

Adnan said the email appeared to have been sent by Associate Professor of Mathematics Brent Carswell and offered him $300 per week for a research project. The email address used the professor’s name and Allegheny’s “.edu” domain before ending in “@gmail.com,” which alerted Adnan that it was not valid. “I knew it was fake,” Adnan said. “Because it happened to me before.”

Michael Burlingham, ’30, mentioned that he received an email from Allegheny warning students the scam. He said the warning email gave him a “mental checklist” of things to look for when dealing with suspicious emails.

“I do feel like it prepared me to be able to tell when someone’s trying to scam me,” Burlingham said.

Even with the college’s cybersecurity measures, Yeung emphasized the importance of staying alert. “Our strongest cyber controls are well-informed users,” she said.

She also encouraged students to be cautious with unexpected emails, even when they appear to come from someone they know. “If you had all sensed that little spidey sense that maybe something might be off, don’t forward it to anybody, stop and verify it via an alternative communication.” Yeung said. Her advice to students is to “Be a little wary.”

Extracted Entities