Point Loma Nazarene University experienced a phishing attack between October 7 and October 20, 2014, resulting in unauthorized access to five employee email accounts. Potentially compromised data includes names, Social Security numbers, credit card numbers, CVV codes, expiration dates, usernames, passwords, dates of birth, and driver’s license numbers. The University disabled affected accounts, changed passwords, blocked phishing URLs, and is implementing two-factor authentication. Complimentary identity protection services were offered to affected individuals.