Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Boston College, Calif. State University computers hacked

School officials say the hackers apparently weren't after personal data

March 17, 2005 12:00 PM ET

Computerworld - A computer used for fund-raising activities at Boston College was hacked into last week, initially raising concerns that personal information, including Social Security numbers, of some 120,000 alumni might have been compromised.
Although BC alerted the affected alumni to the breach, the college is now sure that no personal data was stolen, said BC spokesman Jack Dunn.
The break-in at BC is the second such incident to be reported this week by a university. On Monday, officials at California State University in Chico disclosed that hackers had broken into a housing and food service system containing personal information -- including the names and Social Security numbers -- of about 59,000 current, former and prospective students, faculty and staff.
A statement on the school's Web site said the intruders apparently installed rootkit software on the system for storing music, movie and game files. They also attempted to break into other university computers, the school said.
At BC, Dunn said the hacker planted a program that would launch attacks against other computers.
"Last week, our IT department discovered a security breach on a computer that was managed by a third-party vendor and located in our student calling center," Dunn said. "During a routine monitoring of the computers, IT noticed a spike in activity on this particular computer, and when they discovered the breach, they immediately took the computer off-line, secured the breach and launched an extensive computer forensics investigation."
Dunn said the investigation concluded that the computer wasn't targeted to access personal information but to allow the hacker to launch remote attacks.
"IT has done a thorough investigation, and they have determined the personal information, including Social Security numbers, was not accessed," Dunn said. "But given the seriousness of the issue, we decided to send out the precautionary advisories to all of our alumni on the computer, and we offered guidelines they should consider to insure their privacy."
BC is now purging all Social Security numbers from this computer and will no longer use Social Security numbers as alumni identifiers, Dunn said. He said the school will institute a new identification system.
Dunn said BC has contacted local law enforcement but has not yet contacted state or federal authorities.
In California, officials at California State University are now notifying each person whose name and Social Security number was on the system in accordance with state law. There is no indication that the hackers were targeting confidential information, school officials said.
The compromised system has been "rebuilt and secured," and has been putback onto the university's network. The system is now being reviewed by an outside security firm.
News of the breach comes just as the university has put in place plans to use a new randomly assigned nine-digit ID number for students and employees instead of Social Security numbers.



Jump to comments

Security

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...