E-mail Hack Exposes Student Data at Oregon State

data security illustration with email and padlock symbols

A mid-June data breach at Oregon State University exposed personally identifiable information of 636 students and their families. According to the university, the data breach occurred when an employee's e-mail account was hacked by external people and used to send phishing e-mails across the country. The early investigation by the university IT organization and outside forensics specialists found several documents in the employee's inbox containing the personal information.

The institution said it was "continuing to investigate this matter and determine whether the cyber attacker viewed or copied these documents." All those possibly affected have been notified, the university reported, and they've been offered credit monitoring services for the next year.

The school added that it was also reviewing "the many protection procedures and IT systems the university uses to guard its information systems, e-mail accounts, and student and family records" and would continue monitoring "such efforts and systems, and take further steps to protect the university's information technology and sensitive data."

Outside security experts expressed concern about the lack of detail in the university's explanation. "An effective DNS security layer would have been able to quickly show if any data was sent out of the network," said Cath Goulding, chief information security officer at Nominet, a company that sells such security products, in a statement.

"Academic institutions are a growing target because they hold personally identifiable information for tens of thousands of students, employees, donors and partners. Once it reaches the dark web, this PII can be used for identity theft, synthetic identity creation and robotic account takeovers. Malicious actors can create sophisticated phishing attacks given information available from other data breaches, which is what makes this type of attack so dangerous," added Ben Goodman, senior vice president at security company ForgeRock. "Education institutions must keep pace with attackers by educating their employees to prevent these attacks, while utilizing modern behavioral analytics, 'Know Your Customer' and identity-proofing tools to fight against fraudsters."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • woman speaking into microphone

    Best Practices for Designing Higher-Ed AV Environments

    Cloud-based management, interoperability, and upfront planning are helping campuses build AV infrastructure that performs at scale.

  • data figures moving across a network

    Addressing the Cyber Skills Gap: Retention & Recruitment Secrets from Higher Education

    Institutions are working to ensure the retention and recruitment of top cyber talent by continually investing in professional development, fostering collaborative work environments, and equipping teams with the latest tools available to protect and defend against threats.

  • Abstract digital cloudscape of glowing interconnected clouds and radiant lines

    Cloud Complexity Outpacing Human Defenses, Report Warns

    According to the 2026 Cloud Security Report from Fortinet, while cloud security budgets are rising, 66% of organizations lack confidence in real-time threat detection across increasingly complex multi-cloud environments, with identity risks, tool sprawl, and fragmented visibility creating persistent operational gaps despite significant investment increases.

  • workshop participants discuss sustainability in open science and research

    Open Source: Advancing Our Digital Commons

    IT leaders are recognizing the benefits of a return to open strategies. CT asked Jack Suess, VP of IT and CIO at UMBC, for his views on returning to the digital commons of open source.