Georgia Tech Breach Strikes Possible 1.3 Million

broken padlock

Georgia Tech recently went public about a data breach — the second in less than a year — that could have exposed the personal information of up to 1.3 million people. The cause: a custom web application with a form that was vulnerable to SQL injection.

In mid-2018, Tech suffered data exposure when the university mistakenly sent personal details of almost 8,000 College of Computing students to fellow students as part of an invitation to a conference. The list was accidently attached to the e-mail.

The institution uncovered the latest unauthorized access on March 21, when developers for the school "noticed a significant performance impact" in one of its web applications (which has since been patched). From there, cyber criminals were able to gain access to a "central database."

The security team was able to trace the first of a series of unauthorized breaches to Dec. 14, 2018. By April 2, the institution had begun notifying those affected, including current and former faculty, students, staff and student applicants. The information available on the database included names, addresses, internal ID numbers, dates of birth and social security numbers. It didn't include financial information, health records, grades or research data.

Georgia Tech is working with forensic and data analysis firms, as well as its own police force and the FBI.

"We continue to investigate the extent of the data exposure and will share more information as it becomes available," the institute stated on its website. "We apologize for the potential impact on the individuals affected and our larger community. We are reviewing our security practices and protocols and will make every effort to ensure that this does not happen again."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • cloud with binary code and technology imagery

    Report: Hybrid and AI Expansion Outpacing Cloud Security

    A new survey from the Cloud Security Alliance (CSA) and Tenable finds that rapid adoption of hybrid, multi-cloud and AI systems is outpacing the security measures meant to protect them, leaving organizations exposed to preventable breaches and identity-related risks.

  • wooden blocks with human icons and artificial intelligence symbol

    Report: AI Adoption Leads to Retraining, not Replacing, Workers

    Despite fears that artificial intelligence will lead to major workforce reductions, a new report from the Federal Reserve Bank of New York suggests that’s not happening happening ... yet.

  • Lemony device

    Lemony Introduces On-Prem AI Device for Enterprises

    Artificial intelligence startup Lemony has launched a hardware-based device designed to enable enterprises to run generative AI systems on premises without relying on the cloud.

  • stylized figures, resumes, a graduation cap, and a laptop interconnected with geometric shapes

    OpenAI to Launch AI-Powered Jobs Platform

    OpenAI announced it will launch an AI-powered hiring platform by mid-2026, directly competing with LinkedIn and Indeed in the professional networking and recruitment space. The company announced the initiative alongside an expanded certification program designed to verify AI skills for job seekers.