Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


04:30 PM
Connect Directly

University Of Virginia BreachTargeted Two Individuals With China Links

Latest example of threat actors seeking to exfiltrate data by going after individuals.

A recently disclosed cyberattack at the University of Virginia in Charlottesville has become another example of the growing trend by attackers to exfiltrate sensitive data by targeting specific individuals within organizations.

Earlier this month, UVA officials disclosed that federal authorities had informed the university of a potential intrusion into its networks originating from China. The university confirmed the breach June 21 but did not immediately disclose the incident until last week while it worked to remediate the issue.

Security firm Mandiant, which was hired to investigate the intrusion, has confirmed that the attack appears to have been targeted at two specific employees whose work has a connection to China, university spokesman Anthony de Bruyn told Dark Reading today. According to Mandiant, there is evidence that the attackers accessed the email accounts of the two individuals, de Bruyn says.

He did not disclose what information the attackers may have been able to access from the email accounts or what specifically the two employees were working on pertaining to China.

There is no evidence that the attackers managed to access any university research information, he says. Similarly, no personally identifiable information such as Social Security numbers, personal health information or bank account information appears to have been compromised.

Like many other organizations, UVA did not immediately disclose the breach after being informed about it by federal law enforcement. Instead, the university’s IT organization worked quietly with Mandiant to identify and shut down the threat.

“In order to best protect against future attacks and in keeping with cybersecurity best practices, we notified the community as soon as we were confident that notification would not jeopardize our efforts to secure system,” de Bruyn says. “It was important that the hackers remain unaware of our action to investigate this event and protect against it. If the University had not taken this course of action, the situation could have worsened.”

The intrusion is another example of attackers choosing to target specific individuals to get access to key enterprise data. Other recent examples include advanced persistent threat attacks such as DarkHotel targeting traveling executives and a 2013 cyber espionage campaign against Norwegian telecom firm Telenor.

In UVA’s case, it is not clear what the China-based threat actors were after specifically. But it is possible the attack was motivated by UVA’s links to numerous private and government research organizations via its UVA Research Park, a 562-acre facility that is home to numerous laboratory, medical, pharmaceutical, retail, defense, and intelligence-affiliated organizations.

A report in the Daily Beast Friday postulated that the attack might have something to do with the university’s links to several US defense and intelligence organizations. The report quoted a bulletin issued by the US Department of Defense in July, weeks after the UVA breach, about foreign threat actors targeting academic institutions and government contractors.

The Daily Beast quoted the bulletin as warning government contractors and other organizations of an APT actor penetrating several US organizations and stealing data, credentials and other data.

“These attacks emphasize the need to extend better protection to all employees,” says Richard Stiennon, principal analyst at IT-Harvest and author of “There Will Be Cyberwar.” “Most organizations already have separate protection profiles for senior executives,” to mitigate the threat, he says.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
8/25/2015 | 3:04:24 AM
Re: Internal Involvement
For know it seems that we'll have to wait to have this answer...
User Rank: Ninja
8/24/2015 | 1:11:18 PM
Internal Involvement
So are the reports stating that the two employees that were the points of entry willingly involved or unknowingly exploited?
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
8/21/2015 | 10:22:42 PM
Situations like this present the difficulty with the notion of "security by obscurity."  In any sufficiently sized operation, you're bound to have at least one or two people who are targets in and of themselves for reasons that have nothing to do with the organization -- thereby putting the entire organization and all of its employees, partners, and customers at risk.
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
NetCAT Vulnerability Is Out of the Bag
Dark Reading Staff 9/12/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P3 (, contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P2 (, contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.