CSIDB logo
Incident

University of Ghana

Incident posture

Attack window
Aug 2019
Location
Ghana
Status
Historical
CIA posture
Available to members
Updated
2025-11-03 00:00

Linked entities

Victim
University of Ghana
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The University of Ghana experienced a cybersecurity incident involving its accommodation registration portal, which was compromised by hackers who redirected students to a fraudulent site during the housing registration process. While the university administrator acknowledged the breach, specific details regarding the impact—such as potential data theft, malware deployment, or misuse of redirected information—were not disclosed publicly, leading to concerns about transparency and the risks posed to affected individuals.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around August 30, 2019, the University of Ghana's accommodation registration portal was compromised by hackers. The attackers altered the portal's functionality to redirect students attempting to register for university housing to a fraudulent website. This incident disrupted the housing allocation process for accepted students during a period of high demand for on-campus residences. The Daily Graphic, a Ghanaian news outlet, attempted to obtain details from the Dean of Students but received no response. A university administrator, speaking anonymously, confirmed the breach to journalists, stating the hackers had successfully infiltrated the system to manipulate student registration pathways. The university did not release an official public statement acknowledging the compromise at the time of reporting.

The precise technical scope of the attack and full extent of consequences remained unclear due to insufficient disclosure from university authorities. While the confirmed attacker action involved redirecting students to an illegitimate registration site, the article raised unresolved questions about whether the fraudulent site deployed malware or harvested sensitive personal information from affected students. No verifiable evidence emerged regarding data exfiltration, financial losses, or secondary attacks stemming from the incident. The university's anonymous acknowledgment represented its only documented response, with no further details provided about containment measures, forensic investigations, system restoration timelines, or notifications to potentially impacted individuals. This lack of transparency left critical questions unanswered about operational disruptions, data security implications, and mitigation efforts following the breach.

Sources

Sources available to members: 1 source.

CSIDB