Ohio State is responding to a recent security incident involving a compromised Qualtrics account that was used to distribute phishing messages to university and external recipients.
The incident was identified on Sept. 27, when Qualtrics detected suspicious activity and automatically disabled the affected account. An initial review determined that an unauthorized individual gained access to the account and used it to create a survey and automated workflow designed to send phishing links.
Approximately 8,900 Ohio State email addresses were targeted by the phishing campaign. University email security tools blocked the vast majority of messages before delivery. A limited number of messages reached inboxes, and affected recipients were notified directly.
The unauthorized user also attempted to send phishing messages to external recipients using an uploaded contact list. Qualtrics detected unusual activity and suspended the account, preventing further use.
The university is working closely with Qualtrics to conduct a comprehensive review of the incident and strengthen protections against similar activity in the future. The investigation has identified that the account was accessed through a legacy login method that did not require Ohio State's standard single sign-on process. Ohio State and Qualtrics are evaluating options to reduce risk associated with this authentication pathway while maintaining support for essential system accounts.
How to Handle Suspicious Messages
Members of the Ohio State community are encouraged to remain vigilant when reviewing unexpected emails, surveys or requests for information.
If you receive a suspicious message:
- Do not click links or open attachments.
- Do not respond to the sender.
- Report suspected phishing attempts through established university reporting channels.
- If you believe you entered your credentials into a suspicious website, change your password immediately at my.osu.edu.
Cybersecurity threats continue to evolve, making awareness and prompt reporting important parts of protecting both personal and university information. Additional guidance is available on Ohio State's phishing awareness and cybersecurity education resources.
Use Strong Passwords
Passwords are your best defense to protect your data and prevent attacks on your devices. Keep these guidelines in line as you set passwords for your accounts:
- Never reuse passwords: Use a unique password for every account and service you have. If one account is compromised in a data breach, cybercriminals may try the same password to access your other accounts.
- Make Passwords Complex and Strong: A strong password is your first defense against cybercriminals. Ohio State requires using at least 15 characters. Never reuse passwords across accounts.
- Password Managers: These services generate, store, and manage complex passwords for various accounts. They encrypt your logins and ensure that you have unique passwords for each online account. Though the university does not recommend specific commercial products, we suggest finding one you like and stick with it.
- Monitoring Services: Companies exist to monitor your credit and login credentials for a fee. A free option you can explore is HaveIBeenPwned, which checks to see if your personal data has been compromised in a data breach.
Get Help
- Qualtrics: For questions about Qualtrics surveys or survey administration, contact Survey Support at OTDI-surveysupport@osu.edu.
- Passwords: More specific requirements for Ohio State passwords are outlined after you log in to my.osu.edu.
- Security Breach: If you believe you have clicked on a harmful link or have visited a risky website that may have infected your device, report an incident at security@osu.edu to get help.
- Report Phishing: Use the report-phish@osu.edu email or the Report Suspicious Button in Outlook to report phishing attack messages; reports will be reviewed by the Email Security Team and Incident Response Team.
- General Questions: Contact otdi-dst@osu.edu if you have general questions about security or if you are unsure who to contact.