Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

8/21/2015
04:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

University Of Virginia BreachTargeted Two Individuals With China Links

Latest example of threat actors seeking to exfiltrate data by going after individuals.

A recently disclosed cyberattack at the University of Virginia in Charlottesville has become another example of the growing trend by attackers to exfiltrate sensitive data by targeting specific individuals within organizations.

Earlier this month, UVA officials disclosed that federal authorities had informed the university of a potential intrusion into its networks originating from China. The university confirmed the breach June 21 but did not immediately disclose the incident until last week while it worked to remediate the issue.

Security firm Mandiant, which was hired to investigate the intrusion, has confirmed that the attack appears to have been targeted at two specific employees whose work has a connection to China, university spokesman Anthony de Bruyn told Dark Reading today. According to Mandiant, there is evidence that the attackers accessed the email accounts of the two individuals, de Bruyn says.

He did not disclose what information the attackers may have been able to access from the email accounts or what specifically the two employees were working on pertaining to China.

There is no evidence that the attackers managed to access any university research information, he says. Similarly, no personally identifiable information such as Social Security numbers, personal health information or bank account information appears to have been compromised.

Like many other organizations, UVA did not immediately disclose the breach after being informed about it by federal law enforcement. Instead, the university’s IT organization worked quietly with Mandiant to identify and shut down the threat.

“In order to best protect against future attacks and in keeping with cybersecurity best practices, we notified the community as soon as we were confident that notification would not jeopardize our efforts to secure system,” de Bruyn says. “It was important that the hackers remain unaware of our action to investigate this event and protect against it. If the University had not taken this course of action, the situation could have worsened.”

The intrusion is another example of attackers choosing to target specific individuals to get access to key enterprise data. Other recent examples include advanced persistent threat attacks such as DarkHotel targeting traveling executives and a 2013 cyber espionage campaign against Norwegian telecom firm Telenor.

In UVA’s case, it is not clear what the China-based threat actors were after specifically. But it is possible the attack was motivated by UVA’s links to numerous private and government research organizations via its UVA Research Park, a 562-acre facility that is home to numerous laboratory, medical, pharmaceutical, retail, defense, and intelligence-affiliated organizations.

A report in the Daily Beast Friday postulated that the attack might have something to do with the university’s links to several US defense and intelligence organizations. The report quoted a bulletin issued by the US Department of Defense in July, weeks after the UVA breach, about foreign threat actors targeting academic institutions and government contractors.

The Daily Beast quoted the bulletin as warning government contractors and other organizations of an APT actor penetrating several US organizations and stealing data, credentials and other data.

“These attacks emphasize the need to extend better protection to all employees,” says Richard Stiennon, principal analyst at IT-Harvest and author of “There Will Be Cyberwar.” “Most organizations already have separate protection profiles for senior executives,” to mitigate the threat, he says.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JuliaNorma
50%
50%
JuliaNorma,
User Rank: Apprentice
8/25/2015 | 3:04:24 AM
Re: Internal Involvement
For know it seems that we'll have to wait to have this answer...
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/24/2015 | 1:11:18 PM
Internal Involvement
So are the reports stating that the two employees that were the points of entry willingly involved or unknowingly exploited?
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
8/21/2015 | 10:22:42 PM
Security
Situations like this present the difficulty with the notion of "security by obscurity."  In any sufficiently sized operation, you're bound to have at least one or two people who are targets in and of themselves for reasons that have nothing to do with the organization -- thereby putting the entire organization and all of its employees, partners, and customers at risk.
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/20/2019
Pledges to Not Pay Ransomware Hit Reality
Robert Lemos, Contributing Writer,  6/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12960
PUBLISHED: 2019-06-25
LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d.
CVE-2019-12961
PUBLISHED: 2019-06-25
LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
CVE-2019-12962
PUBLISHED: 2019-06-25
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
CVE-2019-12963
PUBLISHED: 2019-06-25
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
CVE-2019-12964
PUBLISHED: 2019-06-25
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.