Cyber Incident Victim: American Institutes for Research
Timeline
Summary
Unauthorized access to a server at the American Institutes for Research compromised unencrypted personal information of approximately 6,500 current and former employees, including Social Security numbers and payment card details. The organization engaged a digital forensics firm to investigate, notified affected individuals, and offered complimentary credit monitoring services, while confirming no evidence of data misuse and no impact to student or client information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In May 2014, the American Institutes for Research (AIR) experienced unauthorized access to one of its servers containing sensitive employee information. The organization discovered the breach on May 12, 2014, prompting immediate investigation. Forensic analysis revealed that approximately 6,500 current and former staff members had their unencrypted personal data exposed, including Social Security numbers and payment card details. The compromised server housed business systems rather than student or client information, limiting the scope to internal personnel records. Attackers gained entry through unspecified means, though no evidence suggested data extraction or misuse at the time of discovery. AIR confirmed the breach impacted only employee-related systems, with no compromise of external stakeholder data. Notification letters dated May 14, 2014, were prepared for distribution to affected individuals within days of detection.

AIR engaged a digital forensics firm to conduct a comprehensive investigation following the server intrusion. All impacted employees received direct notification and were offered complimentary credit monitoring services for one year as a protective measure. David Myers, AIR's President and CEO, emphasized in the notification correspondence that forensic reviews had not identified any actual misuse of the exposed information. The organization maintained operational continuity while addressing the breach, focusing on securing affected systems and verifying data integrity. No additional attacks or related incidents were reported following the initial unauthorized access event. The response prioritized transparency with affected staff while safeguarding ongoing business functions unrelated to the compromised server.
