Click here to receive your FREE subscription to Campus Technology
Home > Data Security: 13 Breaches Reported So Far This Month
News
Data Security: 13 Breaches Reported So Far This Month
1/25/2008
By David Nagel
A breach at Baylor University is the latest in a string of a more than a dozen data security incidents on United States campuses reported by a variety of sources so far in January 2008. According to a report yesterday in Baylor's campus newspaper,
The Lariat, a student employee accessed the IDs of 526 users of the university's communications service, the Baylor Information Network. It was the second suspected "inside job" reported this month at a university.
Insider IncidentsIn the Baylor incident, according to
The Lariat, there was no theft of Social Security numbers or financial information. However, the information obtained did provide access to the affected users' e-mail and Blackboard accounts. Upon discovering the breach, Baylor's IT department shut down the Baylor Information Network, which remains offline, and notified affected individuals. The FBI is currently investigating the matter, according to the paper.
Earlier this month, another insider job was reported over at Central Piedmont Community College in North Carolina. There, according to campus security watchdog ESI (Educational Security Incidents) and North Carolina NBC affiliate WCNC, a student worker was arrested New Year's Day and charged with embezzlement. She's also under investigation for possible charges relating to identity theft when a supervisor noted that she'd copied down Social Security numbers and birthdates from employee records.
It's worth noting that insider crime did make the top-10 list of security threats to watch in 2008 in a report issued this month by the SANS Institute. It came in at No. 5.
"Insider attacks are initiated by rogue employees, consultants, and/or contractors of an organization," the institute said in its "Top Ten Cyber Security Menaces for 2008" report, issued Jan. 14. "Insider-related risk has long been exacerbated by the fact that insiders usually have been granted some degree of physical and logical access to systems, databases, and networks that they attack, giving them a significant head start in attacks that they launch. More recently, however, security perimeters have broken down, something that allows insiders to attack both from the inside and from outside an organization's network boundaries. Insider-related risk (as well as outsider risk) has thus skyrocketed. Organizations need to put into place substantial defenses against this kind of risk, one of the most basic of which is limiting access according to what users need to do their jobs."
Data Exposure, Losses, BreachesBeyond insider attacks, January has so far seen several incidents of lost hard drives, exposure of user information on the Web, and outright hacks penetrating network defenses.
SSNBreach.org has reported this month five incidents in which colleges and universities posted user information online. These include:
Recommended Reading
- College of Southern Nevada Implementing Angel To Run Online Courses
The College of Southern Nevada (CSN), a community college in Las Vegas with 41,000 students, has adopted the Angel Learning Management Suite (LMS) to support its online course offerings. In Spring 2008 CSN began evaluating alternatives to WebCT, which it currently runs, and made the decision to adopt Angel in the fall. In January 2009, CSN's 865 sections of online enrollment will be delivered using the Angel LMS.
- Toshiba Brings DisplayLink to Docking Station
Toshiba has introduced a new USB docking station that incorporates DisplayLink--a technology that allows computers to connect to projectors and other types of displays through USB 2.0.
- Mitsubishi Ships SXGA+ Projector with DICOM Simulation
Mitsubishi has begun shipping a new LCD-based SXGA+ projector aimed at higher education, specifically medical schools. The new MH2850U, according to Mitsubishi, is "specially engineered for projecting DICOM simulation images for use in medical education and training."
- First Look: Komodo IDE 5.0
Last month, ActiveState released Komodo IDE 5.0, the company's latest integrated development environment (IDE). Komodo supports multiple programming and markup languages, including HTML, JavaScript, PHP, Perl, Java, Python, C++ and more. It does not support some .NET languages at present, such as ASP/ASP.NET, C# and VB.NET.
- IBM Offers Cloud Computing Help
IBM last week announced consulting services specifically designed to help organizations assess their options in using cloud computing technology. "Cloud computing" is a much argued term, but it typically refers to solutions delivered over the Internet, rather than via customer premises-installed software.
- Hollins U Chooses Omnilert for Emergency Notification Ahead of VA Deadline
Hollins University, among other higher ed institutions in Virginia, has implemented Omnilert's e2Campus emergency notification system (ENS) just ahead of a state-mandated deadline requiring them at every public institution of higher education by Jan. 1. Hollins itself isn't a public campus, but wished to implement an ENS before the end of the year, the school said in a company statement.