Hackers raid U. of Nebraska database with 654k Social Security nos.

Vandals gained access to a database containing the personal records, including Social Security numbers, of hundreds of thousands of University of Nebraska students, alumni and others connected to the school's four campuses.

How many victims? 654,000.

What type of personal information? Social Security numbers, addresses, grades, transcripts, and housing and financial aid information for current and former NU students (some dating back to 1985), in addition to employees, parents and student applicants who may or may not have attended NU. Also the bank account information for some 30,000 students was involved.

What happened? The breach was detected late Wednesday and announced Friday. School officials said there is no evidence that any of the information was downloaded, but that the intruder[s] behind the attack were skilled and sophisticated.

What was the response? The school already has notified the students whose bank account numbers were involved in the breach. The other victims also will be notified. The university has contracted a forensic firm to help investigate.

Details: The school is reportedly close to determining the culprit's identity.

Quote: "We're putting together a full summary of events to replicate some of the things the hacker did so we can have a better understanding of what data was accessible,” Joshua Mauk, NU's information security officer, said. “We want to know the full ramifications of what he had access to.”

Source: Omaha.com, Omaha World-Leader, "Authorities have lead on possible NU hacker," May 28, 2012.

JournalStar.com, Lincoln Journal Star, "Employees, many parents in NU database breach," May 27, 2012.

Editor's note: SCMagazine.com tried to reach the university to learn why the database was network connected, and whether the school has any policies in place regarding the use of Social Security numbers. We will update if we hear back.

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.