Eric Walstrom
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Eric Walstrom, also known by the alias Eric Walstrom, is a threat actor located in the United States of America who came to public attention in December 2014 for unauthorized access to the computer systems of New Dorp High School on Staten Island. A sixteen‑year‑old junior at the school, he used programming skills acquired at an elite summer computer camp to bypass password protections and security software, thereby gaining entry to the school’s internal network from his personal smartphone. Once inside, he repeatedly accessed his own report cards and transcripts between mid‑December and early February and altered the grades to reflect higher scores. The activity was detected when an IT staff member noticed irregular logins, prompting the school to involve law enforcement, which led to his arrest and charges that included forgery, computer trespass, unauthorized use of a computer, computer tampering and criminal possession of forgery devices.
The incident illustrates a targeting pattern focused on the education sector, specifically a public high school in New York City, with the actor’s strategic objective limited to improving his personal academic record rather than pursuing financial gain, espionage or disruptive outcomes. His tactics relied on exploiting known vulnerabilities in the school’s authentication and software defenses, employing a self‑configured remote access channel via smartphone that he established after overcoming the initial password barrier. The actor’s tooling consisted primarily of his own programming knowledge in languages such as Java and C++, which he had learned at the iD Programming Academy for Teens, and he did not deploy any malware or third‑party exploit frameworks; instead, he used legitimate networking techniques to maintain persistent access to the compromised system.
No public evidence links Eric Walstrom to any state‑sponsored group, criminal consortium or broader hacking collective, and his actions have been treated as an isolated case of individual misconduct. The case is frequently cited as an example of how insider‑threat‑style behavior can emerge from a student with technical training who chooses to apply those skills for personal advantage within a trusted environment. While the incident did not involve large‑scale data theft or service disruption, it highlighted the importance of monitoring anomalous login activity and securing remote access vectors, lessons that have been echoed in subsequent guidance for educational institutions seeking to protect their internal networks from credential‑based abuse.
Incidents
Attributed incidents are available to members.
1 incident