Skip to main content
California Department of Education Logo

Spear Phishing Email Warning

The California Department of Education (CDE) has been made aware of spear phishing email cyberattacks targeting personnel at local educational agencies.

Spear phishing emails are customized messages sent to specific individuals that appear to come from a trusted source, such as the CDE. These emails are sent by malicious actors who want to steal your sensitive information, such as passwords, bank account, or personal data. These emails may contain links to fake websites that look like the CDE's official site, or attachments that contain malware that can infect your computer or network. If you receive such an email, do not click on any links, or open any attachments, and report the email to your information technology department immediately.

Please be aware that all emails from the CDE will have a domain of @cde.ca.gov, and the primary CDE public website has a web address of www.cde.ca.gov.

Spear Phishing Email Example

The display name of the sender reads “California Department of Education,” but the From address includes @icloud.com instead of @cde.ca.gov. The email body contains personalized details, making it appear legitimate, and creates urgency by saying it will "expire after 24 hours," which is a common phishing tactic. Furthermore, when hovering over the "CLICK HERE TO UPDATE..." button/link, the destination web address does not include .cde.ca.gov.

Example of a spear phishing email - accessible description provided above image.

If the “CLICK HERE TO UPDATE..” button is selected, the user is directed to a web page that looks like the home page for the CDE’s public website. The web page automatically displays a modal window that asks for sensitive personal information.

Web page that looks like the CDE home page with modal window asking for sensitive personal information.

However, by inspecting the information in the web address section of the web browser, the user will notice the domain name ends in pantheonsite.io (instead of cde.ca.gov).

Browser address bar showing a non-CDE domain name

Additional Resources

Questions:   Information Security & Privacy Office | iso@cde.ca.gov
Last Reviewed: Friday, August 30, 2024
Related Content
Trending in Education Technology
Recently Posted in Education Technology
  • Spear Phishing Email Warning (added 30-Aug-2024)
    The California Department of Education (CDE) has been made aware of spear phishing email cyberattacks targeting personnel at local educational agencies.