E-mail Hack Exposes Student Data at Oregon State

data security illustration with email and padlock symbols

A mid-June data breach at Oregon State University exposed personally identifiable information of 636 students and their families. According to the university, the data breach occurred when an employee's e-mail account was hacked by external people and used to send phishing e-mails across the country. The early investigation by the university IT organization and outside forensics specialists found several documents in the employee's inbox containing the personal information.

The institution said it was "continuing to investigate this matter and determine whether the cyber attacker viewed or copied these documents." All those possibly affected have been notified, the university reported, and they've been offered credit monitoring services for the next year.

The school added that it was also reviewing "the many protection procedures and IT systems the university uses to guard its information systems, e-mail accounts, and student and family records" and would continue monitoring "such efforts and systems, and take further steps to protect the university's information technology and sensitive data."

Outside security experts expressed concern about the lack of detail in the university's explanation. "An effective DNS security layer would have been able to quickly show if any data was sent out of the network," said Cath Goulding, chief information security officer at Nominet, a company that sells such security products, in a statement.

"Academic institutions are a growing target because they hold personally identifiable information for tens of thousands of students, employees, donors and partners. Once it reaches the dark web, this PII can be used for identity theft, synthetic identity creation and robotic account takeovers. Malicious actors can create sophisticated phishing attacks given information available from other data breaches, which is what makes this type of attack so dangerous," added Ben Goodman, senior vice president at security company ForgeRock. "Education institutions must keep pace with attackers by educating their employees to prevent these attacks, while utilizing modern behavioral analytics, 'Know Your Customer' and identity-proofing tools to fight against fraudsters."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Glowing digital padlock breaking into tiny cubic fragments over complex circuit board background

    Report: Basic Security Failures Continue to Fuel Enterprise Breaches

    Despite years of investment in cybersecurity technologies, many enterprise breaches still begin with familiar weaknesses, according to a new report from SonicWall.

  • person typing on a touch screen schedule plan calendar

    DOJ Extends Deadline for ADA Title II Compliance

    Institutions working to meet the Americans with Disabilities Act Title II regulations for digital accessibility have received a temporary reprieve: The United States Department of Justice has published an interim final rule to push back the compliance deadline by one year.

  • abstract data flow

    Google Intros New Gemini Enterprise Agent Platform

    Google Cloud has announced a new platform for building and managing enterprise AI agents, as the company seeks to turn its Gemini models and Vertex AI tooling into a broader system for automating business workflows.

  • layered glass panels and light trails

    Stanford Online Launches Immersive Learning Studio

    Stanford Online recently marked its 30th anniversary with the announcement of a new immersive learning studio, according to a university news release. The studio takes advantage of AI-powered and immersive learning technologies to continue delivering personalized and faculty-led education.