Cyber Security

University of California data breach: Sensitive information of staff, students leaked

The University of California (UC) has released further details of a data breach affecting staff and students, confirming that sensitive information was taken in the attack.

As previously reported by The Daily Swig, the institution suffered a data leak in April after malicious actors gained unauthorized access via third-party service Accellion file transfer appliance (FTA).

The UC released further information last night (May 10) about the incident, which affected employees (current and former) and their dependents, retirees and beneficiaries, and current students, as well as other individuals who participated in UC programs.

Impacted information “may include” full names, addresses, telephone numbers, Social Security numbers, driver’s license information, passport information, financial information including bank routing and account numbers, health and related benefit information, disability information and birthdates, as well as other personal information, said the UC.

Individuals who applied for courses starting in the academic year 2021-22 may have also had their contact details, including names, phone numbers, and addresses, stolen.

More secure solution

In light of the cyber-attack, UC said it has stopped using Accellion FTA and is transitioning to a “more secure solution”.

The university is offering free credit monitoring to all those affected and will be holding workshops designed to help individuals protect themselves against possible identity theft.

The UC has not confirmed the number of people involved, but has confirmed it is conducting an investigation with the help of the FBI and “cybersecurity experts”.

The statement reads: “These investigations take time, and we are working deliberately, while taking care to provide accurate information, as quickly as we can.

“Within the next 45-60 days, we expect to send appropriate individual notifications through Experian to those people whose personal information was impacted, where current contact details are available to the university.”

UC added: “When we discovered the issue, we took the system offline and patched the Accellion vulnerability. There is no evidence that other university systems were impacted.

“We have decommissioned FTA, and are in the process of transitioning to a new file transfer system with enhanced security controls, deploying additional system monitoring broadly throughout our network, conducting a security health check of certain systems, and enhancing security controls, processes, and procedures.

“We are also reviewing and updating our security policies, procedures and controls as appropriate.”

Source: https://portswigger.net/daily-swig/university-of-california-data-breach-sensitive-information-of-staff-students-leaked

Click to comment

You May Also Like

Government

NEW YORK (AP) — Damien, age 5, was giddy with excitement as he left a Manhattan homeless shelter, sometimes running and skipping along the...

Cyber Security

The cyberattack that ultimately led to the breach of several U.S. officials’ email accounts was the result of a China-based threat actor accessing a...

Government

SEATTLE (AP) — A high school football coach in Washington state who won his job back after the U.S. Supreme Court ruled he could...

Cyber Security

The nation’s cyber defense agency is building onto White House efforts to secure schools’ systems nationwide with the help of major education software companies....

Copyright © 2023 Newsworthy News | Global | Political | Local | All News | Website By: Top Search SEO

Exit mobile version