Consensus: Decentralized IT Led to Boulder Hack

The University of Colorado at Boulder reported that a hacker May 12 exposed about 45,000 students' names and Social Security numbers. The incident affected students enrolled at any time from 2002 to the present, the school said.

The hacked server was in the College of Arts and Sciences' academic advising center. Dan Jones, director of the Campus IT Security Office, told the Denver Post that the center's firewall was turned off, and a patch was not properly installed on the system's anti-virus program.

School administrators said they would cut their practice of distributing IT responsibilities among colleges, schools, departments, and programs and assigned the school's central information technology department to take over the IT management of the center.

University officials also told the Post they do not believe the hacker targeted students' personal information. "It looked like someone was trying to seize control of the machine and not the data,"' a school spokesman told the newspaper. "And in the process of that, the data was exposed. But we're erring on the side of caution."

Read More:

About the Author

Paul McCloskey is contributing editor of Syllabus.

Featured

  • silhouette of business person facing wall of data

    Why AI Strategy Belongs in the President's Office

    Institutions that are succeeding with AI share one thing in common, and it is not a better committee, a larger budget, or a more sophisticated technology stack. It is a president who never handed off the steering wheel.

  • Jason Palm

    AI, Identity, and Speed: Cybersecurity Priorities for Higher Ed

    Fortinet Security Operations Specialist Jason Palm explains how AI is raising new security challenges for higher education, requiring stronger governance, identity protection, threat detection, automation, and incident readiness.

  • Neon blue security locks with a single red highlight

    AI Shifts Cybersecurity Focus from Finding Flaws to Fixing Them

    For decades, one of cybersecurity's most difficult challenges has been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

  • Man types on laptop in data center

    Point-in-Time Restore Now Generally Available for Windows 11

    Microsoft has made point-in-time restore generally available for Windows 11, giving users and IT administrators a built-in way to roll back PCs after bad updates, driver problems, app corruption, or other issues.