Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


04:30 PM
Connect Directly

University Of Virginia BreachTargeted Two Individuals With China Links

Latest example of threat actors seeking to exfiltrate data by going after individuals.

A recently disclosed cyberattack at the University of Virginia in Charlottesville has become another example of the growing trend by attackers to exfiltrate sensitive data by targeting specific individuals within organizations.

Earlier this month, UVA officials disclosed that federal authorities had informed the university of a potential intrusion into its networks originating from China. The university confirmed the breach June 21 but did not immediately disclose the incident until last week while it worked to remediate the issue.

Security firm Mandiant, which was hired to investigate the intrusion, has confirmed that the attack appears to have been targeted at two specific employees whose work has a connection to China, university spokesman Anthony de Bruyn told Dark Reading today. According to Mandiant, there is evidence that the attackers accessed the email accounts of the two individuals, de Bruyn says.

He did not disclose what information the attackers may have been able to access from the email accounts or what specifically the two employees were working on pertaining to China.

There is no evidence that the attackers managed to access any university research information, he says. Similarly, no personally identifiable information such as Social Security numbers, personal health information or bank account information appears to have been compromised.

Like many other organizations, UVA did not immediately disclose the breach after being informed about it by federal law enforcement. Instead, the university’s IT organization worked quietly with Mandiant to identify and shut down the threat.

“In order to best protect against future attacks and in keeping with cybersecurity best practices, we notified the community as soon as we were confident that notification would not jeopardize our efforts to secure system,” de Bruyn says. “It was important that the hackers remain unaware of our action to investigate this event and protect against it. If the University had not taken this course of action, the situation could have worsened.”

The intrusion is another example of attackers choosing to target specific individuals to get access to key enterprise data. Other recent examples include advanced persistent threat attacks such as DarkHotel targeting traveling executives and a 2013 cyber espionage campaign against Norwegian telecom firm Telenor.

In UVA’s case, it is not clear what the China-based threat actors were after specifically. But it is possible the attack was motivated by UVA’s links to numerous private and government research organizations via its UVA Research Park, a 562-acre facility that is home to numerous laboratory, medical, pharmaceutical, retail, defense, and intelligence-affiliated organizations.

A report in the Daily Beast Friday postulated that the attack might have something to do with the university’s links to several US defense and intelligence organizations. The report quoted a bulletin issued by the US Department of Defense in July, weeks after the UVA breach, about foreign threat actors targeting academic institutions and government contractors.

The Daily Beast quoted the bulletin as warning government contractors and other organizations of an APT actor penetrating several US organizations and stealing data, credentials and other data.

“These attacks emphasize the need to extend better protection to all employees,” says Richard Stiennon, principal analyst at IT-Harvest and author of “There Will Be Cyberwar.” “Most organizations already have separate protection profiles for senior executives,” to mitigate the threat, he says.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
8/25/2015 | 3:04:24 AM
Re: Internal Involvement
For know it seems that we'll have to wait to have this answer...
User Rank: Ninja
8/24/2015 | 1:11:18 PM
Internal Involvement
So are the reports stating that the two employees that were the points of entry willingly involved or unknowingly exploited?
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
8/21/2015 | 10:22:42 PM
Situations like this present the difficulty with the notion of "security by obscurity."  In any sufficiently sized operation, you're bound to have at least one or two people who are targets in and of themselves for reasons that have nothing to do with the organization -- thereby putting the entire organization and all of its employees, partners, and customers at risk.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.