• News/
  • https://www.bleepingcomputer.com/news/security/stanford-data-of-27-000-people-stolen-in-september-ransomware-attack/

Stanford: Data of 27,000 people stolen in September ransomware attack

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 12, 2024
·
Updated

Stanford University says the personal information of 27,000 individuals was stolen in a ransomware attack impacting its Department of Public Safety (SUDPS) network. The university discovered the attack on September 27 and disclosed one month later that it was investigating a cybersecurity incident impacting SUDPS systems. In an update published on Monday, Stanford said the attackers didn't gain access to other systems outside the Department of Public Safety's network. "The investigation determined that an unauthorized individual(s) gained access to the Department of Public Safety's network between May 12, 2023, and Sept. 27, 2023," the university said. According to data breach notifications filed with Maine's Attorney General, the attackers stole documents containing personally identifiable information (PII) belonging to 27,000 individuals. "The personal information that may have been affected varies from person to person but could include date of birth, Social Security number, government ID, passport number, driver's license number, and other information the Department of Public Safety may have collected in its operations," Stanford added. "For a small number of individuals, this information may also have included biometric data, health/medical information, email address with password, username with password, security questions and answers, digital signature, and credit card information with security codes." While Stanford has not attributed the September incident to a spec...

Read full article

Affected Software

1 affected component
VMware ESXi
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a ransomware attack on Stanford University that resulted in the theft of personal information from 27,000 individuals.

2

What security implications are discussed?

The article highlights the risk of personal data exposure and potential identity theft following the ransomware attack.

3

What products or software are affected?

The affected software mentioned in the article is VMware ESXi.

4

When did Stanford University discover the ransomware attack?

Stanford University discovered the ransomware attack on September 27.

5

Which department at Stanford University was impacted by the attack?

The Department of Public Safety (SUDPS) network was impacted by the attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Stanford: Data of 27,000 people stolen in September ransomware attack - SecAlerts