Penn State Hit Twice by Malware-Related Data Breaches

A cached database containing private information is troubling Pennsylvania State University staff, as is an infected computer in its library system. The university made a public announcement recently that it had found a computer in its Outreach Market Research and Data office that was communicating with a bot controller, thereby exposing nearly 16,000 Social Security numbers to possible compromise. A bot is malware that enables its instigator to gain control over the computer running it.

According to Penn State the computer had at one time contained a database for the institution's use. That had been removed when the institution stopped using Social Security numbers in 2005; however, an archived copy remained undetected in the computer's cache.

In compliance with a state law regulating the breach-of-personal information, the university has sent out letters to those included in the database to warn them of the possible breach. But administrators said that they have no evidence the data has been used or even accessed by unauthorized users.

"Even when theft is only a remote possibility, we alert anyone who may have been affected, and arm them with information and steps to take to mitigate their risk," said Sarah Morrow, chief privacy officer.

The university also recently reported a similar breach that occurred on a library computer that may have exposed data on 9,766 people. They too received information from the university on preventing data theft. No other details were available.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • The AI Show

    Register for Free to Attend the World's Greatest Show for All Things AI in EDU

    The AI Show @ ASU+GSV, held April 5–7, 2025, at the San Diego Convention Center, is a free event designed to help educators, students, and parents navigate AI's role in education. Featuring hands-on workshops, AI-powered networking, live demos from 125+ EdTech exhibitors, and keynote speakers like Colin Kaepernick and Stevie Van Zandt, the event offers practical insights into AI-driven teaching, learning, and career opportunities. Attendees will gain actionable strategies to integrate AI into classrooms while exploring innovations that promote equity, accessibility, and student success.

  • cloud, database stack, computer screen, binary code, and flowcharts interconnected by lines and arrows

    Salesforce to Acquire Data Management Firm Informatica

    Salesforce has announced plans to acquire data management company Informatica for $8 billion. The deal is aimed at strengthening Salesforce's AI foundation and expanding its enterprise data capabilities.

  • stylized AI code and a neural network symbol, paired with glitching code and a red warning triangle

    New Anthropic AI Models Demonstrate Coding Prowess, Behavior Risks

    Anthropic has released Claude Opus 4 and Claude Sonnet 4, its most advanced artificial intelligence models to date, boasting a significant leap in autonomous coding capabilities while simultaneously revealing troubling tendencies toward self-preservation that include attempted blackmail.

  • NVIDIA DGX line

    NVIDIA Intros Personal AI Supercomputers

    NVIDIA has introduced a new lineup of AI-powered computing solutions designed to accelerate enterprise workloads.