# CrowdStrike Compromised Password Information

Beginning October 20th, 2025, students, faculty, and staff will receive automated notifications from CrowdStrike informing them that their password has been detected as compromised.

<span data-ogsc="rgb(0, 0, 0)">This message originating from </span><span data-ogsc="rgb(0, 120, 212)">[falcon@crowdstrike.com](mailto:falcon@crowdstrike.com "mailto:falcon@crowdstrike.com")</span><span data-ogsc="rgb(0, 0, 0)"> is legitimate and does not indicate any malicious activity. Recipients of these messages should be aware that a password change must be completed prior to 5:00 PM the day of receipt. If this is not completed before that time, a password change will be **required** at their next login.</span>

This process is executed daily, with regular updates to the compromised password databases. As a result, passwords previously considered secure may subsequently be flagged as compromised and require resetting.

All students, faculty, and staff passwords are continually monitored under this protocol to ensure A-State resources remain secure.

<span class="s3">Below is an example of the email users will receive if their password is flagged as compromised:</span>

[![Crowdstrike.png](https://kb.astate.edu/uploads/images/gallery/2025-10/scaled-1680-/crowdstrike.png)](https://kb.astate.edu/uploads/images/gallery/2025-10/crowdstrike.png)

Tips for identifying these emails as non-malicious:

1\. The sender address is [<span class="s1">falcon@crowdstrike.com</span>](mailto:falcon@crowdstrike.com)

2\. This message is marked as “from an external sender” due to CrowdStrike not being an internal resource.

3\. This message requires no action from the recipient. There are <span class="s2">**no** </span>forms, <span class="s2">**no** </span>requests for a reply, and <span class="s2">**no** </span>directions to reply from an email address not associated with A-State.

4\. No user information is requested. As this is from a legitimate source, any necessary information is already available to the ITS Security Team.

If you ever doubt the legitimacy of an email or communication, reports can be submitted to [<span class="s1">security@astate.edu</span>](mailto:security@astate.edu) for review.