Connecticut community college hit with "zero-day" malware

A Connecticut community college reported the potential exposure of confidential records following a malware infection.

How many victims? 87,000 records of staff, students and faculty members at Housatonic Community College (HCC) in Bridgepoint, Conn.

What type of personal information? Names, Social Security numbers, addresses and dates of birth.

What happened? “Zero-day" malware” infected two computers in campus offices and was discovered during a nightly scan of the network. The compromised machines were removed from the offices and sent for forensic analysis in Hartford, where it was confirmed that the potentially exposed files contained confidential information.

What was the response? HCC is sending letters to the individuals whose records were compromised and offering two years of free identity theft protection.

Details: The school plans to change how confidential information is accessed on its systems and will add new software to prevent viruses. Officials at the college said there is no indication that any personal data was actually stolen.

This is the second college in Connecticut this year to succumb to a major malware infestation.

Quote: “We take the protection of personal information very seriously and are taking steps to prevent future occurrences through a combination of new technical and operational controls,” said HCC President Anita Gliniecki.

Source: ctpost.com, Connecticut Post, “HCC records potentially exposed in security breach,” April 13, 2012. connecticut.cbslocal.com, CBS Connecticut, “Data Breach At Community College,” April 12, 2012.

close

Next Article in The Data Breach Blog

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.