Dear Caltech Community,
Thank you for your continued diligence and partnership in helping protect Caltech from cyber threats.
Recently, Information Security conducted a phishing simulation modeled after a Canvas-related phishing scenario. Given the heightened awareness following the Canvas security incident, this simulation provided us with an important opportunity to assess how effectively our community can identify and respond to suspicious messages.
I am pleased to share that the Caltech community continues to demonstrate strong cybersecurity awareness. The Q2 2026 phishing simulation resulted in an overall compromise rate of 3.27%, well below our FY26 strategic goal of maintaining phishing susceptibility below 5%.
Our long-term objective is to sustain phishing failure rates below 3% across all divisions while continuing to enhance training, awareness, and testing programs across campus.
Stay Vigilant: Verify Canvas Links Before Clicking
Attackers frequently impersonate trusted services such as Canvas to steal credentials or distribute malware. Before clicking any Canvas-related link:
- Verify that the URL points to caltech.Instructure.com or another official Instructure.com subdomain (such as community.Instructure.com).
- Hover your mouse over links (or long-press on mobile devices) to inspect the destination before clicking.
- Be cautious of unexpected requests to sign in, verify your account, or provide personal information.
Report Suspicious Messages
- If you receive a suspicious email, please report it immediately within Outlook by selecting the message and then clicking on the Report Phishing button from the toolbar/home tab.
- Reporting suspicious messages helps Information Security investigate potential threats and protect the Caltech community.
Our Shared Responsibility
Cybersecurity is a team effort. Every phishing email detected, every suspicious message reported, and every link verified before clicking contributes to protecting Caltech's research, teaching, and administrative operations.
While no simulation can replicate every real-world attack, your participation helps us strengthen our defenses and identify areas where additional awareness and training may be beneficial.
Thank you again for your continued diligence and partnership in protecting Caltech from cyber threats.
Sincerely,
Ash Hadi
Chief Information Security Officer, IMSS