Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Ohio University reports two separate security breaches

One incident may have compromised the Social Security numbers of 137,000 alumni
 

Sign up to receive Business Intelligence Resource Alerts

May 3, 2006 (Computerworld) -- Ohio University this week disclosed two separate but apparently unrelated incidents of data theft involving its computers.

On April 24, IT officials at the university noticed that someone had hacked into an alumni database server containing personal and biographical information for more than 300,000 individuals and organizations, said Bill Sams, the Athens-based university’s CIO. Faculty and staff members hired by the school before January 2004 were also affected.

The compromised files did not include credit card or bank information, but they did include Social Security numbers for 137,800 individuals, Sams said.

The breach was discovered after IT officials noticed the affected server was being used to launch a denial-of-service attack against an external target, Sams said.

“We immediately took it off-line and got into the logs. We discovered that it had been compromised as far back as 2005,” he said. In the 13 months since the server was breached, “we have found that people have accessed it from both domestic and international IP addresses,” he said.

The compromised server was supposed to have been decommissioned more than a year ago, and IT officials assumed the system had been taken off-line, Sams said. As a result, it had not received any security updates and patches for more than a year. He did not disclose how the server was breached or what operating system was running on it.

The second data compromise involved a server at the Technology Transfer Department, which is part of the University’s Innovation Center. FBI officials told the university about that breach on April 21. The server, which contained patent data and intellectual property files, was apparently involved in another incident that the FBI was investigating, Sams said, without providing further details. The university had no idea that the server had been broken into until the FBI pointed it out, he said.

The FBI is currently investigating both incidents, he said.

Ohio University today started sending out e-mails to those affected by the hack of the alumni database server. “We are sending them at the rate of 10,000 an hour,” Sams said. He added that the University has also set up a Web site providing details about the incident and instructing affected individuals on the steps they can take to mitigate the risk of ID theft.




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
Data exposure: Using software to redact personal data from public documents
FBI: No credit card data breach in N.H. state server case
Security snafu at Boston Globe exposes subscriber data
'Human error' exposes patients' Social Security numbers in N.C.
Ohio University reports two separate security breaches
Data exposure: Counties across the U.S. posting sensitive info online
Arrests made in debit card fraud case
Lessons learned from corporate security breaches
Idaho utility hard drives -- and data -- turn up on eBay
N.H. IT worker disputes state government security breach
Registrar's database said to have exposed data
Bank tape lost with data on 90,000 customers
Creative Bungling: IT Can't Stop All Data Breaches
Offshore outsourcing cited in Florida data leak
Aetna says laptop stolen with data on 38,000 members
FTC imposes $10M fine against ChoicePoint for data breach
Debit card fraud outbreak raises questions about data breach
Honeywell blames ex-employee in data leak
Update: Thief nabs backup data on 365,000 patients
Confidential patient data sent to wrong company -- for 15 months
Ohio recalls voter registration CDs; Social Security numbers included
Laptop theft at Fidelity exposes data on 196,000 HP workers
Analysis: Data breach notification law unlikely this year
Hacker hits Georgia state database via hole in security software
Update: Fla. residents' data exposure a statewide issue
"Need help sorting through the hype of cloud computing? Here's some IDC research on the benefits, barriers -- and what..." Read more...
"Stephen Spoonamore offers more details on what I was trying to drive home in my recent column: Because individual votes..." Read more...
Read more Security posts or See all Blogs
IBM launches Bluehouse, a Facebook for business
iPhone grabs top smart phone spot
Oracle tries to step up on high-end databases
More top stories...
Microsoft scales out SQL Server 2008, wants to 'democratize BI'
Virtual Headaches
Filters on in-flight Wi-Fi may be just the start
Too much junk food, too little exercise and a 24/7 tether to technology? Your body ain't happy, friend. Let us count the pains.
Instruments on the surface of Mars have detected falling snow that is likely evaporating before it reaches the planet.
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
Getting new software installed on Linux doesn't have to be hard, but it can differ depending on what you're installing.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
The Enterprise Search Zone
Software as a Service Zone

Ads by TechWords

See your link here
Speeding the time to intelligence
Get this Computerworld report free for a limited time, compliments of SAS.
Time To Intelligence -- a concept defining how long it takes to get accurate and timely information into the hands of workers who need it most. Do it slower than your competitors and your company is toast. Do it faster, you scorch them. Business Intelligence is the key to optimizing Time To Intelligence, and success there is a combination of people, policies, and technology.
Download this executive briefing download
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary webcast today!
Go to the webcast 
Rapid application development, rapid results
Download this special report now!
(Source: Intersystems) All too many businesses suffer from IT infrastructures that are a hodge-podge of disconnected databases and applications. What's needed is the ability rapidly develop connected applications under a unified service-oriented architecture. InterSystems Ensemble integration environment and Cache database are effective tools in answering this need, delivering a rapid ROI.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Project Portfolio Management - Boost the value of IT
Core Network Services Survey: The Costs and Impacts of DNS and IP Address Management
Six Project Metrics Every CIO Should Know for Application Delivery Success
View more whitepapers