CrowdStrike Compromised Password Information Beginning October 20th, 2025, students, faculty, and staff will receive automated notifications from CrowdStrike informing them that their password has been detected as compromised. This message originating from falcon@crowdstrike.com  is legitimate and does not indicate any malicious activity. Recipients of these messages should be aware that a password change must be completed prior to 5:00 PM the day of receipt. If this is not completed before that time, a password change will be required  at their next login. This process is executed daily, with regular updates to the compromised password databases. As a result, passwords previously considered secure may subsequently be flagged as compromised and require resetting. All students, faculty, and staff passwords are continually monitored under this protocol to ensure A-State resources remain secure. Below is an example of the email users will receive if their password is flagged as compromised: Tips for identifying these emails as non-malicious: 1. The sender address is falcon@crowdstrike.com 2. This message is marked as “from an external sender” due to CrowdStrike not being an internal resource. 3. This message requires no action from the recipient. There are no forms, no requests for a reply, and no directions to reply from an email address not associated with A-State. 4. No user information is requested. As this is from a legitimate source, any necessary information is already available to the ITS Security Team. If you ever doubt the legitimacy of an email or communication, reports can be submitted to security@astate.edu for review.