Advertisement
Promo

Security threats Toolkit

University suffers massive ID data theft

Declan McCullagh CNET News

Published: 11 Jan 2005 08:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

George Mason University confirmed on Monday that the personal information of more than 30,000 students, faculty and staff had been nabbed by online intruders.

The attackers broke into a server that held details used on campus identity cards, the university said. Joy Hughes, the school's vice-president for information technology, said in an internal email sent over the weekend and seen by ZDNet UK sister site CNET News.com that "the server contained the names, photos, Social Security numbers and [campus ID] numbers of all members of the Mason community who have identification cards".

Hughes warned that campus community members should contact the major credit bureaus to flag their accounts for possible identity fraud. "It appears that the hackers were looking for access to other campus systems rather than specific data," Hughes wrote. "However, it is possible that the data on the server could be used for identity theft."

George Mason is a public university located in Fairfax, Virginia, a suburb of Washington, DC, with smaller campuses in Arlington, Virginia, and Prince William County. It reported 26,796 students enrolled as of autumn 2002, and 3,908 faculty and staff members.

It also is home to the Information Security Institute, the Lab for Information Security Technology and the Centre for Secure Information Systems, which has been designated a "Centre of Academic Excellence" by the US National Security Agency.

Last year, George Mason said it would cease to print Social Security numbers on campus ID cards and would instead generate unique "G numbers" for each student and each member of faculty and staff.

That was in reaction to a Virginia state law, enacted as a response to identity fraud concerns, that required state agencies and universities to change their practices. But the server with the ID card information still stored Social Security numbers in its database, according to the George Mason email.

"We felt that the information there was secure," George Mason spokesman Daniel Walsch said on Monday. The school discovered the breach on 3 January and university police are investigating, he said.

George Mason is not alone among universities in suffering a security breach. Two years ago, online intruders broke into a server containing the credit card numbers of some 57,000 patrons of a Georgia Institute of Technology arts and theatre programme, while others lifted more than 55,000 Social Security numbers from computers at the University of Texas at Austin. Last year, more than one million California residents had their personal information leaked thanks to a pair of incidents at UCLA and the University of California at Berkeley.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
134 out of 247 people found this useful


Full Talkback thread

0 comments

Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters