Stanford University says the personal information of 27,000 individuals was stolen in a ransomware attack impacting its Department of Public Safety (SUDPS) network. The university discovered the attack on September 27 and disclosed one month later that it was investigating a cybersecurity incident impacting SUDPS systems. In an update published on Monday, Stanford said the attackers didn't gain access to other systems outside the Department of Public Safety's network. "The investigation determined that an unauthorized individual(s) gained access to the Department of Public Safety's network between May 12, 2023, and Sept. 27, 2023," the university said. According to data breach notifications filed with Maine's Attorney General, the attackers stole documents containing personally identifiable information (PII) belonging to 27,000 individuals. "The personal information that may have been affected varies from person to person but could include date of birth, Social Security number, government ID, passport number, driver's license number, and other information the Department of Public Safety may have collected in its operations," Stanford added. "For a small number of individuals, this information may also have included biometric data, health/medical information, email address with password, username with password, security questions and answers, digital signature, and credit card information with security codes." While Stanford has not attributed the September incident to a spec...
Stanford: Data of 27,000 people stolen in September ransomware attack
BleepingComputer
·Sergiu Gatlan
·Published Mar 12, 2024
·Updated
Affected Software
1 affected component
VMware ESXi
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a ransomware attack on Stanford University that resulted in the theft of personal information from 27,000 individuals.
2
What security implications are discussed?
The article highlights the risk of personal data exposure and potential identity theft following the ransomware attack.
3
What products or software are affected?
The affected software mentioned in the article is VMware ESXi.
4
When did Stanford University discover the ransomware attack?
Stanford University discovered the ransomware attack on September 27.
5
Which department at Stanford University was impacted by the attack?
The Department of Public Safety (SUDPS) network was impacted by the attack.