E-mail Hack Exposes Student Data at Oregon State

data security illustration with email and padlock symbols

A mid-June data breach at Oregon State University exposed personally identifiable information of 636 students and their families. According to the university, the data breach occurred when an employee's e-mail account was hacked by external people and used to send phishing e-mails across the country. The early investigation by the university IT organization and outside forensics specialists found several documents in the employee's inbox containing the personal information.

The institution said it was "continuing to investigate this matter and determine whether the cyber attacker viewed or copied these documents." All those possibly affected have been notified, the university reported, and they've been offered credit monitoring services for the next year.

The school added that it was also reviewing "the many protection procedures and IT systems the university uses to guard its information systems, e-mail accounts, and student and family records" and would continue monitoring "such efforts and systems, and take further steps to protect the university's information technology and sensitive data."

Outside security experts expressed concern about the lack of detail in the university's explanation. "An effective DNS security layer would have been able to quickly show if any data was sent out of the network," said Cath Goulding, chief information security officer at Nominet, a company that sells such security products, in a statement.

"Academic institutions are a growing target because they hold personally identifiable information for tens of thousands of students, employees, donors and partners. Once it reaches the dark web, this PII can be used for identity theft, synthetic identity creation and robotic account takeovers. Malicious actors can create sophisticated phishing attacks given information available from other data breaches, which is what makes this type of attack so dangerous," added Ben Goodman, senior vice president at security company ForgeRock. "Education institutions must keep pace with attackers by educating their employees to prevent these attacks, while utilizing modern behavioral analytics, 'Know Your Customer' and identity-proofing tools to fight against fraudsters."

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Complete College America Launches Center to Boost Data-Driven Student Success Strategies

    National nonprofit Complete College America (CCA) recently launched the Center for Leadership, Institutional Metrics, and Best Practices (CLIMB), with the goal of helping higher education institutions use data-driven strategies to improve student outcomes.

  • teacher

    6 Policy Recommendations for Incorporating AI in the Classroom

    The Southern Regional Education Board's Commission on AI in Education has published six recommendations for states on adopting artificial intelligence in schools, colleges, and universities. The guidance marks the commission's first release since it was established last February, with more recommendations planned in the coming year.

  • computer screen displaying a landline phone being unplugged from a single cord, with a modern office desk, keyboard, and subtle lighting in the background

    Microsoft to Discontinue Skype Services

    Microsoft has announced that it is shutting down service for its Skype telecommunications and video calling services on May 5, 2025.

  • Two figures, one male and one female, stand beside a transparent digital interface displaying AI symbols like neural networks, code, and a shield, against a clean blue gradient background.

    Report Makes Business Case for Responsible AI

    A new report commissioned by Microsoft and published last month by research firm IDC notes that 91% of organizations use AI tech and expect more than a 24% improvement in customer experience, business resilience, sustainability, and operational efficiency due to AI in 2024.