CSIDB logo
Incident

Far Eastern University

Incident posture

Attack window
Jun 2020
Location
Philippines
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Far Eastern University
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Far Eastern University experienced a cybersecurity incident involving a potential data breach that exposed approximately 1,000 student records. The event coincided with cyberattacks targeting multiple Philippine universities, including compromised subdomains at another institution and unauthorized access to student portals elsewhere, raising broader concerns about educational sector vulnerabilities. The incident prompted student anxieties regarding personal information security amid a series of similar disruptions affecting academic institutions.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 17, 2020, Far Eastern University (FEU) reported a potential data breach involving the exposure of approximately 1,000 student records. The disclosure coincided with cyberattacks targeting multiple Philippine educational institutions that same day, including Cebu Normal University's compromised library and journal subdomains. FEU did not publicly specify the exact nature of the breach, the systems involved, or the specific types of student data potentially exposed. The incident emerged during a surge in attacks against Philippine universities, with San Beda University and the University of the Philippines Visayas also reporting cyber incidents earlier in June 2020. No technical details regarding FEU's breach vector—such as malware, phishing, or unauthorized access methods—were disclosed in available reports.

The breach announcement generated immediate concerns among FEU students regarding the security of their personal information, though no subsequent reports confirmed misuse of exposed data. FEU's public response lacked documented specifics about containment measures, forensic investigations, or system restoration timelines. The incident occurred amid heightened vulnerability across Philippine academic institutions transitioning to online operations during the COVID-19 pandemic. Other affected universities, including Cebu Normal University, suspended compromised subdomains and issued public statements via social media, but comparable mitigation details from FEU remain unverified in source materials. Cybersecurity monitoring groups observed a pattern of opportunistic attacks targeting educational portals during this period, though no threat actor claimed responsibility for the FEU incident.

Sources

Sources available to members: 1 source.

CSIDB