Penn State Hit Twice by Malware-Related Data Breaches

A cached database containing private information is troubling Pennsylvania State University staff, as is an infected computer in its library system. The university made a public announcement recently that it had found a computer in its Outreach Market Research and Data office that was communicating with a bot controller, thereby exposing nearly 16,000 Social Security numbers to possible compromise. A bot is malware that enables its instigator to gain control over the computer running it.

According to Penn State the computer had at one time contained a database for the institution's use. That had been removed when the institution stopped using Social Security numbers in 2005; however, an archived copy remained undetected in the computer's cache.

In compliance with a state law regulating the breach-of-personal information, the university has sent out letters to those included in the database to warn them of the possible breach. But administrators said that they have no evidence the data has been used or even accessed by unauthorized users.

"Even when theft is only a remote possibility, we alert anyone who may have been affected, and arm them with information and steps to take to mitigate their risk," said Sarah Morrow, chief privacy officer.

The university also recently reported a similar breach that occurred on a library computer that may have exposed data on 9,766 people. They too received information from the university on preventing data theft. No other details were available.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Abstract speed motion blur in vibrant colors

    3 Ed Tech Shifts that Will Define 2026

    The digital learning landscape is entering a new phase defined by rapid advances in artificial intelligence, rising expectations for the student experience, and increasing pressure to demonstrate quality and accountability in online education.

  • A panel discussion from SXSW EDU 2025

    12 Ways to Dive into AI at SXSW EDU

    This March 9-12, the SXSW EDU Conference & Festival returns to Austin, TX, to celebrate innovation, experimentation, and learning across every stage of education.

  • abstract cybersecurity data protection

    Rubrik Intros Google Workspace Data Protection

    Rubrik has announced the launch of Rubrik Data Protection for Google Workspace, a product the company said is designed to help enterprise customers protect data and restore operations across Google Workspace environments.

  • college students sitting with laptops at an outdoor table

    How Colleges Are Building More Connected and Responsive Student Support

    Colleges are making steady progress in building more connected and responsive student support systems. By aligning services and improving coordination, institutions are enhancing both the student and staff experience.