In a breach notice from Virginia Commonwealth University, CIO Mark Willis said the school has detected unauthorized access to a server containing personal data on current and former VCU and VCU Health System staff and students.
"On October 24, routine monitoring of servers supporting a VCU system uncovered suspicious files on one of the devices," the notice says. "The server was taken offline and a forensic investigation was launched to identify what unauthorized activities had taken place and the vulnerabilities that led to the compromise. The vulnerabilities have been corrected, and it has been determined that this server contained no personal data.
"Five days later, VCU’s continuing investigation revealed two unauthorized accounts had been created on a second server, which also was taken offline," the notice continues. "Subsequent analysis showed the intruders had compromised this device through the first server. The intruders were on the server a short period of time and appeared to do nothing other than create the two accounts."
Files on the second server contained data on 176,567 individuals, including either a name or eID, Social Security number, and, in some cases, date of birth and contact information, according to the notice.
"Our investigation was unable to determine with 100 percent certainty that the intruders did not access or copy the files in question," the notice says. "We believe the likelihood that they did is very low." The university says it is informing those affected both by email and by first-class mail.
Have a comment on this story? Please click "Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
What's Next for Certificate Technology
A recent rash of certificate authority breaches has left a bad taste in many people's mouths. There is no one reason for the breaches. The compromises were the result of a breakdown in people, processes and technology, but not necessarily the certificates themselves. We take a look at what?s wrong with certificate technology, what can be done to fix it, and what's down the road for certificates and CAs.
Will Smartcards Live Up to Their Name?
Recent compromises of smartcard data have exacerbated concerns about the technology?s privacy, security and standards (or lack thereof). Yet the promise of smartcards is too compelling to ignore. New technologies and applications prompt us to take a fresh look.
Get The Best Of Biometrics
As data volume and sensitivity grow, companies cannot rely on password- and token-based authentication. Biometrics can be used to provide strong access control, but you must weigh added complexity and costs against assurance that users are who they say they are.
Other reports from the Authentication Tech Center:
MORE NEWSFEED >>>