Home > Data Security: 13 Breaches Reported So Far This Month

News

Data Security: 13 Breaches Reported So Far This Month

1/25/2008

A breach at Baylor University is the latest in a string of a more than a dozen data security incidents on United States campuses reported by a variety of sources so far in January 2008. According to a report yesterday in Baylor's campus newspaper, The Lariat, a student employee accessed the IDs of 526 users of the university's communications service, the Baylor Information Network. It was the second suspected "inside job" reported this month at a university.

Insider Incidents
In the Baylor incident, according to The Lariat, there was no theft of Social Security numbers or financial information. However, the information obtained did provide access to the affected users' e-mail and Blackboard accounts. Upon discovering the breach, Baylor's IT department shut down the Baylor Information Network, which remains offline, and notified affected individuals. The FBI is currently investigating the matter, according to the paper.

Earlier this month, another insider job was reported over at Central Piedmont Community College in North Carolina. There, according to campus security watchdog ESI (Educational Security Incidents) and North Carolina NBC affiliate WCNC, a student worker was arrested New Year's Day and charged with embezzlement. She's also under investigation for possible charges relating to identity theft when a supervisor noted that she'd copied down Social Security numbers and birthdates from employee records.

It's worth noting that insider crime did make the top-10 list of security threats to watch in 2008 in a report issued this month by the SANS Institute. It came in at No. 5.

"Insider attacks are initiated by rogue employees, consultants, and/or contractors of an organization," the institute said in its "Top Ten Cyber Security Menaces for 2008" report, issued Jan. 14. "Insider-related risk has long been exacerbated by the fact that insiders usually have been granted some degree of physical and logical access to systems, databases, and networks that they attack, giving them a significant head start in attacks that they launch. More recently, however, security perimeters have broken down, something that allows insiders to attack both from the inside and from outside an organization's network boundaries. Insider-related risk (as well as outsider risk) has thus skyrocketed. Organizations need to put into place substantial defenses against this kind of risk, one of the most basic of which is limiting access according to what users need to do their jobs."

Data Exposure, Losses, Breaches
Beyond insider attacks, January has so far seen several incidents of lost hard drives, exposure of user information on the Web, and outright hacks penetrating network defenses.

SSNBreach.org has reported this month five incidents in which colleges and universities posted user information online. These include:


Recommended Reading
  • Tiffin U's New Online College to Use Pearson's eCollege for Course Management

    Beginning this fall, students in Tiffin University's newest online program, Ivy Bridge College, will use eCollege, a course management system from Pearson, for all of their online courses. The 2,350-student Tiffin U is located in Tiffin, OH and offers both on-campus and online classes. Since 2005, those online courses have been managed through Jenzabar Internet Campus Solution.

  • California Community Colleges Adopt SunGard Banner Software

    California's Rio Hondo College and Sierra College have selected software from the Banner Unified Digital Campus and other solutions from SunGard Higher Education to help address their growing enrollments and to help improve student retention and services.

  • Luidia Releases eBeam Interact 2.1 for Interactive Whiteboards

    Luidia has released a new version its eBeam software for use with classroom-based interactive projection environments. eBeam Interact 2.1 offers both new and upgraded features, including enhanced screen recording and a comprehensive online image gallery, as well as the company's Scrapbook Image Writer feature.

  • McGill U Library Scanning Rare Books with Kirtas

    McGill University Library in Montreal will be using a Kirtas Technologies APT BookScan 2400RA to digitize its collections. The company says that the 2400RA is capable of acquiring page images at the rate of 2,400 pages per hour. The library will be working with Ristech, a Canadian reseller, to implement the digitization solution.

  • Ball State U Web Sites Now Managed with Sitecore

    Ball State University in Muncie, IN has gone public regarding its deployment of a Web site content management system from Sitecore. Ball State chose Sitecore's software to revamp its 220-plus sites, integrating common new media applications and garnering a next-generation user experience that has won several awards from education and new media marketing organizations. Now, Ball State maintains uniformity across all university Web sites and said it has enhanced its recruiting efforts through the site's new look and interface.

  • Bio-Key Launches Emergency Alert Platforms for Schools

    Bio-Key International has announced the release of two new emergency alert and management solutions for the education market. MobileSRO is designed specifically for the K-12 environment, while MobileCampus caters to higher education and other campus-based organizations.