Advertisement
Promo

Security threats Toolkit

Ohio University suffers massive security breach

Greg Sandoval CNET News

Published: 12 May 2006 09:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Data thieves may have plundered Social Security numbers and other private information — including health records — belonging to students and faculty at Ohio University, following three separate computer intrusions at the school.

According to a message posted on the school's Web site, more than 200,000 people may have been affected, including past and present students as well as school employees.

Administrators also suggested that more thefts may be uncovered as investigators continue to review computer systems campuswide.

While this is only the latest in a long string of electronic attacks on the nation's universities, the case appears to be unprecedented because of the number of data thefts discovered at one time at one school.

As part of its investigation, the university said on its Web site, it has sought the help of the FBI, forensic consultants and other universities that have suffered similar intrusions "to improve the security of data and IT resources" throughout the university.

"Emails and letters have been or are being sent to all constituents whose personal information may have been compromised," the school said in a statement.

Last month, the FBI alerted the university's administration that a server within the school's Technology Transfer Department had been compromised. Little personal information was believed to be lost in that breach, but a second breach was found three days later on 24 April.

The school's electronic-security team discovered that a server within alumni relations had been commandeered and was being used in a denial of service attack. The Social Security numbers of about 137,000 people were stored in that server.

On Thursday, the school announced that it had found a third intrusion at its health center involving 60,000 people including all current students as well as some school faculty.

In addition to Social Security numbers, the compromised server in the health department held health records.

Last month, a 25-year-old San Diego man was charged with hacking into the University of Southern California's online application system and nabbing personal data from prospective students.

In January, the University of Notre Dame began investigating an electronic break-in that may have exposed the personal and financial information of school donors.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
160 out of 252 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Microsoft App-V: Helpful Tools

I wanted to mention a rather useful tool that have recently come from Microsoft. As quoted by one of the TechNet blogs; "The Microsoft Installer (MSI) Utility for Microsoft Application... More

Post a comment

Microsoft Security Update: The potenti...

The big story with the October 2009 Patch Tuesday Security Update from Microsoft is the sheer size (both breadth and depth) of the update. This is the largest update in the history... More

Post a comment

IE8: Another Application Compatibility...

Getting applications to work on Vista or Windows Server 2008 is not the only compatibility issue that you may encounter. One additional "platform" that you may not have considered is... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters