Hackers raid U. of Nebraska database with 654k Social Security nos.

Vandals gained access to a database containing the personal records, including Social Security numbers, of hundreds of thousands of University of Nebraska students, alumni and others connected to the school's four campuses.

How many victims? 654,000.

What type of personal information? Social Security numbers, addresses, grades, transcripts, and housing and financial aid information for current and former NU students (some dating back to 1985), in addition to employees, parents and student applicants who may or may not have attended NU. Also the bank account information for some 30,000 students was involved.

What happened? The breach was detected late Wednesday and announced Friday. School officials said there is no evidence that any of the information was downloaded, but that the intruder[s] behind the attack were skilled and sophisticated.

What was the response? The school already has notified the students whose bank account numbers were involved in the breach. The other victims also will be notified. The university has contracted a forensic firm to help investigate.

Details: The school is reportedly close to determining the culprit's identity.

Quote: "We're putting together a full summary of events to replicate some of the things the hacker did so we can have a better understanding of what data was accessible,” Joshua Mauk, NU's information security officer, said. “We want to know the full ramifications of what he had access to.”

Source: Omaha.com, Omaha World-Leader, "Authorities have lead on possible NU hacker," May 28, 2012.

JournalStar.com, Lincoln Journal Star, "Employees, many parents in NU database breach," May 27, 2012.

Editor's note: SCMagazine.com tried to reach the university to learn why the database was network connected, and whether the school has any policies in place regarding the use of Social Security numbers. We will update if we hear back.

POLL

More in The Data Breach Blog

Data on patients may be exposed after X-rays go missing

Data on patients may be exposed after X-rays ...

The sensitive information, including names, addresses, and Social Security numbers, went missing from a third-party vendor's warehouse.

Administrative error exposes personal data of 10,200 neurology patients

A routine email sent to Dent Neurologic Institute patients mistakenly included the sensitive data of others receiving treatment.

Website hack leads to credit card breach of nearly 10K at N.C. medical practice

Website hack leads to credit card breach of ...

Other personal information, such as names, contact information and dates of birth, was also compromised.