The ITS Information Security team encourages students, faculty, staff, and researchers to report cybersecurity incidents, suspicious activity, and security vulnerabilities. Prompt reporting helps protect university systems, data, and the campus community.

Report Suspicious or Malicious Email

Report spam, phishing, fraudulent, harassing, or otherwise suspicious email using Gmail’s Report Spam or Report Phishing feature.

Common scams may impersonate UCSB departments, faculty, financial aid notices, account alerts, or job opportunities.

If you receive a suspicious message: 

  • Do not click links, open attachments, or reply 
  • Do not share passwords or personal information 
  • Forward the message to phishing@ucsb.edu if additional review is needed 
  • Delete the email from your inbox 
  • Contact the IT Service Desk immediately if you entered credentials or sensitive information

Report Harassing or Abusive Messages

Do not delete emails involving threats, harassment, discrimination, stalking, fraud, or abusive behavior.
 

Instead:

  • Preserve the original message for reporting 
  • Send a copy to security@ucsb.edu and include full email headers when forwarding 
  • Contact UCSB Police immediately if there is an urgent safety concern.

Reports involving discrimination or sexual misconduct may also be referred to Title IX or campus law enforcement.

Report Scanning, Hacking, or Other Hostile Activity

Report unauthorized access attempts, malware infections, compromised accounts, suspicious network activity, or hacking incidents to security@ucsb.edu

When submitting a report, include:

  • Date and time of the incident
  • Time zone
  • Source and destination IP addresses or hostnames
  • Affected systems or services
  • Destination port, if known
  • Brief description of the event
  • Relevant logs (pasted directly into the email in plain text)

To help investigators respond efficiently:

  • Submit one report per incident
  • Do not send unnecessary information, attachments, duplicate reports, full log archives, ping results, or trace routes

Report a Security Vulnerability

If you discover or suspect a cybersecurity vulnerability on a UCSB-owned or operated system, report it to  security@ucsb.edu immediately and provide as much detail as possible.


Include:

  • Your contact information
  • Affected systems, applications, URLs, or hostnames
  • Description of the vulnerability
  • Steps to reproduce the issue
  • Date and time discovered
  • Potentially affected resources or data

Do not include sensitive personal information in your report.

UCSB reviews all responsibly disclosed vulnerabilities and uses the information to improve campus security. UCSB does not currently operate a formal bug bounty or paid vulnerability disclosure program, and unauthorized scanning or testing of university systems is prohibited.

Addressing Blocked Webpages

 If you are attempting to access a website that has been erroneously blocked by the UCSB firewall, please submit a ServiceNow ticket to report this problem.