March 06, 2003

UT Austin hacked, personal info exposed

Attack yields data on more than 55,000 individuals

An Internet-based attack on computer systems at the University of Texas at Austin yielded personal information on more than 55,000 individuals, including current and former students, current and former faculty, staff and job applicants, according to a statement posted on the university's Web site.

The attack was first detected on Sunday when computer systems personnel at the university noticed that a computer was malfunctioning.

Analysis of the problem revealed that it was the result of an attack and that an administrative data reporting system used by the university had been compromised in that attack, according to the university.

The attacker or attackers apparently used a "blunt force" approach to cracking the system, writing a program that input millions of Social Security numbers to the system. Social Security numbers that matched records in the UT database were captured.

In addition to the victims' Social Security numbers, the attackers gained access to e-mail addresses, titles, phone numbers and university department addresses. Academic and health records were not exposed, the university said.

Approximately 55,200 individuals had some of their data exposed in the attack, the university said.

The university is working with the U.S. Attorney's Office as well as the U.S. Secret Service to locate those responsible for the break-in and is working to contact all of those affected by the attack, it said.

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.