CSIDB logo
Incident

University of Galway

Incident posture

Attack window
May 2022
Location
Ireland
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
University of Galway
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

National University of Ireland Galway encountered an IT security incident prompting the implementation of access restrictions to its online systems. The institution employed Cloudflare security measures to block traffic originating from a specific autonomous system network and associated IP address, preventing unauthorized access attempts to its web infrastructure. This action disrupted connectivity for users within the affected network range attempting to reach the university's online resources.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On or around May 1, 2022, the National University of Ireland Galway (NUI Galway) experienced an IT security incident that prompted external reporting by media outlets. RTE News published an article on May 17, 2022, detailing aspects of the event under the headline referencing NUI Galway's IT security measures. The article's accessibility became restricted shortly after publication due to Cloudflare security protocols implemented by the website owner. Cloudflare's protection system blocked access attempts originating from IP address 143.244.44.167 within autonomous system number 212238, displaying an error message citing an ASN ban. This restriction prevented general public access to the incident details through RTE's platform while preserving the article's metadata including publication date and intended subject matter.

The technical response involved automated security measures that terminated connection attempts from the prohibited network segment. Cloudflare's Ray ID 8423f9929a5341e9 documented the specific transaction where access denial occurred. Performance and security safeguards remained active throughout the restriction period as part of standard web protection protocols. No additional details regarding the university's internal response mechanisms, operational impacts, forensic findings, or recovery processes appeared in the accessible portions of the source material. The incident's public documentation remained limited to these access restriction records without further elaboration on root causes, threat actor attribution, or institutional remediation efforts in the available evidence.

Sources

Sources available to members: 1 source.

CSIDB