By Marc Stoufer III
On Wednesday, Feb. 26, an email that appeared to be from a Grand Rapids Community College student email address, claiming that the recipient’s account was scheduled for deactivation and asking for their personal and banking information to recover it, was sent to many current and former GRCC students.
The email had a Google form attached that prompted students to input their phone number, email address, GRCC student ID, date of birth and answers to both security questions. It also asked for the email and password for BankMobile, the school’s financial transaction system.
“I saw it was formatted incorrectly for being a GRCC official email,” recalled pre-engineering student Chase Kramer.
Less than an hour later, GRCC’s IT department sent a follow-up email to all students, informing them that the email was not legitimate and was part of a phishing scam to obtain information from students who filled out the form.
The IT department encouraged students to report the message to Google and reminded them of best practices when receiving suspicious-looking emails, such as verifying the sender’s address, not clicking on suspicious links, not sharing login credentials and notifying GRCC IT.
After multiple students reported both the email and the form to Google, the form was taken offline. Some students said they were unable to access the email a few days later.
Two days later, IT sent out a second follow-up, this time explaining how phishing scams work, reminding students not to respond to the email or fill out the form, and encouraging them again to report the email to Google. They also suggested that anyone who input their password into the form should “change it immediately—especially if you use the same password elsewhere.”
Six days later, on March 6 at 12:54 p.m., GRCC IT resent that update to students, saying “We have learned that many students did not receive the initial message.” Further information provided in the email was identical to previous warnings.
Sixteen minutes later, a student responded to that email, thanking the department for the information. This response was sent to everybody the initial email was sent to.
Over the next 31 minutes, 73 additional students responded to the email chain. Some thanked the IT department, others expressed their confusion and frustration at the situation. A handful of students responded to say they were enjoying the conversation. Many responded to encourage others to stop responding.
In an email to The Collegiate, GRCC student Rigoberto Contreras-Torres described the phishing scam, IT updates and student replies as “a wild, collective experience,” likening it to “throwing a match into gasoline.
It exposed a vulnerability that students shouldn’t have to worry about,” stated Contreras-Torres.
Kramer expressed his concern with the potential for someone to send any kind of material to the entire student body in one message to a publicly available address. If someone had taken advantage of that access, he said, it “could have been detrimental to the school’s reputation.”
I appreciate being notified,” added Daniel Pierce, “but did not appreciate that the reply contained the email addresses of other GRCC students… those should not be shared.”
For some students, this situation raises security concerns.
“How well is IT equipped to actually protect students’ data from more sophisticated attacks? And most importantly, what’s next? Because if scammers can create chaos this easily, I have to wonder if a bigger security breach is inevitable,” stated Contreras-Torres.
Kramer added that he thought it was “embarrassing for the college if their system is getting abused by students.”
He also suggested that IT should conduct further security tests and publicly tell students the problem is fixed, along with implementing a school-wide password reset.
Executive Director of Marketing & Communications Lyndsie Post, responding on behalf of Chief Information Officer/VP Debra Hintz, clarified that “a small number of students unintentionally shared their login credentials, which led to their accounts being compromised.”
According to Post, the accounts in question were disabled and none of GRCC’s systems were affected. Additionally, five students submitted their BankMobile credentials, but “we have no indication that funds have been taken from these accounts.”
The IT department has not sent any further follow-ups to students.
Collegiate reporter Juliette Bolle-Leon contributed to this article.




