{"id":4170,"date":"2026-05-04T12:36:17","date_gmt":"2026-05-04T19:36:17","guid":{"rendered":"https:\/\/blogschapman.wpenginepowered.com\/information-systems\/?st-import=86aecdf2e9d375b67c55bf5f4f49adbf"},"modified":"2026-07-20T15:44:08","modified_gmt":"2026-07-20T15:44:08","slug":"why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk","status":"publish","type":"post","link":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/","title":{"rendered":"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk"},"content":{"rendered":"<p><span data-contrast=\"auto\">As the CISO at Chapman, I often hear this understandable response when we notify someone that their credentials appeared in an external data breach:\u00a0<\/span><i><span data-contrast=\"auto\">\u201cBut Chapman wasn\u2019t breached.\u201d<\/span><\/i><\/p>\n<p><span data-contrast=\"auto\">That\u2019s\u00a0usually correct,\u00a0and it can still present a real risk.<\/span><\/p>\n<p><span data-contrast=\"auto\">When breaches occur elsewhere on the internet, email addresses and passwords are\u00a0frequently\u00a0exposed. If a password used on another site was also used for a Chapman account, attackers\u00a0don\u2019t\u00a0need to compromise Chapman systems. They simply\u00a0attempt\u00a0to sign in using valid credentials.<\/span><\/p>\n<p><span data-contrast=\"auto\">Attackers are not focused on where a password originated,\u00a0only where it still works.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">How Credential Reuse Leads to Account Compromise<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">Stolen credentials are routinely added to automated testing tools that\u00a0attempt\u00a0to\u00a0log\u00a0in across common services, including university email systems.\u00a0This process doesn\u2019t rely on exploiting vulnerabilities; it relies on successful authentication.<\/span><\/p>\n<p><span data-contrast=\"auto\">If a password is reused and still valid, the account may already be compromised.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">The Role and Limits of MFA<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">Multi-Factor Authentication (MFA)\u00a0remains\u00a0one of our most effective controls and significantly reduces the likelihood of compromise. However, MFA is not immune to human factors.<\/span><\/p>\n<p><span data-contrast=\"auto\">If an attacker already has a valid password, an unexpected MFA prompt may appear. In a busy workday, it can be easy to assume the prompt is legitimate and approve it without investigation.<\/span><\/p>\n<p><span data-contrast=\"auto\">MFA protects systems; user awareness completes the protection.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Why Annual Password Resets Still Matter<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">It\u2019s\u00a0reasonable to ask why Chapman\u00a0requires\u00a0annual password changes, especially when MFA is in place.<\/span><\/p>\n<p><span data-contrast=\"auto\">The answer is simple: password resets limit the lifespan of exposed credentials.<\/span><\/p>\n<p><span data-contrast=\"auto\">External breaches are not always discovered immediately. Credentials can circulate quietly for months \u2014 or years \u2014 before they are actively abused. An annual reset ensures that even if a password was unknowingly exposed elsewhere, it will eventually become unusable.<\/span><\/p>\n<p><span data-contrast=\"auto\">In effect, password resets:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Reduce the window of opportunity for attackers<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Invalidate credentials obtained from older breaches<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Provide a clean reset point when combined with MFA<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Annual resets are not about inconvenience;\u00a0they are a proven way to reduce long-term risk.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Why This Matters for Faculty and Staff<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">Faculty and staff accounts often provide access beyond email, including learning platforms, research data, student records, financial systems, and administrative tools. A single compromised account can be used to send convincing messages, access sensitive information, or enable further attempts within the institution.<\/span><\/p>\n<p><span data-contrast=\"auto\">For this reason, credential security is treated as a shared responsibility across the university, supported by both technical controls and user practices.<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Practical Steps That Make a Real Difference<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">In recognition of\u00a0<\/span><b><span data-contrast=\"auto\">World Password Day on May 7<\/span><\/b><span data-contrast=\"auto\">, this is a good opportunity to review a few practices that meaningfully reduce risk:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><b><span data-contrast=\"auto\">Use a\u00a0<\/span><\/b><a href=\"https:\/\/www.chapman.edu\/campus-services\/information-systems\/security\/password-management.aspx\"><b><span data-contrast=\"none\">unique password for your Chapman account<\/span><\/b><\/a><b><span data-contrast=\"auto\">.<\/span><\/b><br \/>\n<span data-contrast=\"auto\">Reuse is the most common factor in credential compromise.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Use a password manager.<\/span><\/b><br \/>\n<span data-contrast=\"auto\">This enables strong, unique passwords without added effort.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Pause before approving MFA prompts.<\/span><\/b><br \/>\n<span data-contrast=\"auto\">If you did not\u00a0initiate\u00a0the sign-in, treat the prompt as a warning.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Annual password resets should be regarded as an essential security measure rather than a mere procedural requirement.<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Report unusual activity promptly<\/span><\/b><span data-contrast=\"auto\">\u00a0to\u00a0<\/span><a href=\"mailto:abuse@chapman.edu\"><span data-contrast=\"none\">abuse@chapman.edu<\/span><\/a><span data-contrast=\"auto\">\u00a0or\u00a0<\/span><a href=\"mailto:infosec@chapman.edu\"><span data-contrast=\"none\">infosec@chapman.edu.<\/span><\/a><br \/>\n<span data-contrast=\"auto\">Early notification allows us to\u00a0contain\u00a0issues quickly.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><b><span data-contrast=\"auto\">In Closing<\/span><\/b><\/p>\n<p><span data-contrast=\"auto\">Most account compromises do not involve sophisticated attacks. They rely on credential reuse and\u00a0a moment\u00a0of inattention. Our technical controls,\u00a0including MFA and annual password resets,\u00a0work continuously, but they are most effective when paired with informed, engaged users.<\/span><\/p>\n<p><span data-contrast=\"auto\">World Password Day is\u00a0a timely\u00a0reminder that a few deliberate habits go a long way in protecting both individual accounts and the broader Chapman community.<\/span><\/p>\n<p><span data-contrast=\"auto\">Thank you for your partnership in keeping Chapman\u2019s systems and data secure.<\/span><\/p>\n<p><span data-contrast=\"auto\"><br \/>\nStay safe, stay vigilant!<\/span><br \/>\n<span data-contrast=\"auto\">Keith Barros<\/span><br \/>\n<span data-contrast=\"auto\">Chief Information Security Officer (CISO)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the CISO at Chapman, I often hear this understandable response when we notify someone that their credentials appeared in [&hellip;]<\/p>\n","protected":false},"author":3283,"featured_media":3577,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"custom_author_name":"Keith Barros","chapman_pin_hero_slider":"","footnotes":""},"categories":[35,23,246],"tags":[34,36,45],"class_list":["post-4170","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","category-ist","category-online-safety","tag-cybersecurity","tag-infosec","tag-phishing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Information Systems &amp; Technology | Chapman Blogs<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk - Information Systems &amp; Technology\" \/>\n<meta property=\"og:description\" content=\"As the CISO at Chapman, I often hear this understandable response when we notify someone that their credentials appeared in [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Information Systems &amp; Technology\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-04T19:36:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-20T15:44:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png\" \/>\n\t<meta property=\"og:image:width\" content=\"889\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Sarem Yadegari\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sarem Yadegari\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/\"},\"author\":{\"name\":\"Sarem Yadegari\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#\\\/schema\\\/person\\\/d65d5e059be631ad9322745dc1978bfc\"},\"headline\":\"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk\",\"datePublished\":\"2026-05-04T19:36:17+00:00\",\"dateModified\":\"2026-07-20T15:44:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/\"},\"wordCount\":631,\"publisher\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2024\\\/05\\\/CISO-Blog-Banner-e1715360926871.png\",\"keywords\":[\"Cybersecurity\",\"infosec\",\"Phishing\"],\"articleSection\":[\"Information Security\",\"IS&amp;T\",\"Online Safety\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/\",\"url\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/\",\"name\":\"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk - Information Systems &amp; Technology\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2024\\\/05\\\/CISO-Blog-Banner-e1715360926871.png\",\"datePublished\":\"2026-05-04T19:36:17+00:00\",\"dateModified\":\"2026-07-20T15:44:08+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2024\\\/05\\\/CISO-Blog-Banner-e1715360926871.png\",\"contentUrl\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2024\\\/05\\\/CISO-Blog-Banner-e1715360926871.png\",\"width\":889,\"height\":500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/2026\\\/05\\\/04\\\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#website\",\"url\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/\",\"name\":\"Information Systems &amp; Technology\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#organization\",\"name\":\"Information Systems &amp; Technology\",\"url\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2026\\\/03\\\/MasterBrand_000-scaled-1.png\",\"contentUrl\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/wp-content\\\/uploads\\\/sites\\\/68\\\/2026\\\/03\\\/MasterBrand_000-scaled-1.png\",\"width\":2560,\"height\":435,\"caption\":\"Information Systems &amp; Technology\"},\"image\":{\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blogs.chapman.edu\\\/information-systems\\\/#\\\/schema\\\/person\\\/d65d5e059be631ad9322745dc1978bfc\",\"name\":\"Sarem Yadegari\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g\",\"caption\":\"Sarem Yadegari\"},\"url\":\"\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Information Systems &amp; Technology | Chapman Blogs","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/","og_locale":"en_US","og_type":"article","og_title":"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk - Information Systems &amp; Technology","og_description":"As the CISO at Chapman, I often hear this understandable response when we notify someone that their credentials appeared in [&hellip;]","og_url":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/","og_site_name":"Information Systems &amp; Technology","article_published_time":"2026-05-04T19:36:17+00:00","article_modified_time":"2026-07-20T15:44:08+00:00","og_image":[{"width":889,"height":500,"url":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png","type":"image\/png"}],"author":"Sarem Yadegari","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sarem Yadegari","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#article","isPartOf":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/"},"author":{"name":"Sarem Yadegari","@id":"https:\/\/blogs.chapman.edu\/information-systems\/#\/schema\/person\/d65d5e059be631ad9322745dc1978bfc"},"headline":"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk","datePublished":"2026-05-04T19:36:17+00:00","dateModified":"2026-07-20T15:44:08+00:00","mainEntityOfPage":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/"},"wordCount":631,"publisher":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/#organization"},"image":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png","keywords":["Cybersecurity","infosec","Phishing"],"articleSection":["Information Security","IS&amp;T","Online Safety"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/","url":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/","name":"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk - Information Systems &amp; Technology","isPartOf":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#primaryimage"},"image":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png","datePublished":"2026-05-04T19:36:17+00:00","dateModified":"2026-07-20T15:44:08+00:00","breadcrumb":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#primaryimage","url":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png","contentUrl":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2024\/05\/CISO-Blog-Banner-e1715360926871.png","width":889,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/05\/04\/why-it-wasnt-a-chapman-breach-can-still-put-your-account-at-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blogs.chapman.edu\/information-systems\/"},{"@type":"ListItem","position":2,"name":"Why \u201cIt Wasn\u2019t a Chapman Breach\u201d Can Still Put Your Account at Risk"}]},{"@type":"WebSite","@id":"https:\/\/blogs.chapman.edu\/information-systems\/#website","url":"https:\/\/blogs.chapman.edu\/information-systems\/","name":"Information Systems &amp; Technology","description":"","publisher":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blogs.chapman.edu\/information-systems\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/blogs.chapman.edu\/information-systems\/#organization","name":"Information Systems &amp; Technology","url":"https:\/\/blogs.chapman.edu\/information-systems\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.chapman.edu\/information-systems\/#\/schema\/logo\/image\/","url":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2026\/03\/MasterBrand_000-scaled-1.png","contentUrl":"https:\/\/blogs.chapman.edu\/information-systems\/wp-content\/uploads\/sites\/68\/2026\/03\/MasterBrand_000-scaled-1.png","width":2560,"height":435,"caption":"Information Systems &amp; Technology"},"image":{"@id":"https:\/\/blogs.chapman.edu\/information-systems\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/blogs.chapman.edu\/information-systems\/#\/schema\/person\/d65d5e059be631ad9322745dc1978bfc","name":"Sarem Yadegari","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/892c40d5625fcfbebed3cafa00486b7e4c5cc3142768ea78889ac333c3e587c8?s=96&d=mm&r=g","caption":"Sarem Yadegari"},"url":""}]}},"_links":{"self":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/users\/3283"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/comments?post=4170"}],"version-history":[{"count":1,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4170\/revisions"}],"predecessor-version":[{"id":4308,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4170\/revisions\/4308"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/media\/3577"}],"wp:attachment":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/media?parent=4170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/categories?post=4170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/tags?post=4170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}