Menu
Browse

Cyber Incident Victim: Concordia University

Date:

Mar 2016

Location:

Canada

Summary

Concordia University discovered unauthorized keylogger devices installed on express workstations in its Webster and Vanier libraries, which are restricted to short-duration use. The university issued warnings to students and staff who accessed these terminals over a 12-month period, indicating potential exposure of login credentials and sensitive data, particularly from online banking activities. Affected individuals were urged to change passwords associated with institutional accounts as a precautionary measure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 21, 2016, Concordia University notified its community about a potential computer security breach involving unauthorized hardware devices discovered on campus workstations. The university identified keylogger devices—hardware capable of recording keystrokes—attached to express workstations in the Webster and Vanier libraries. These compromised terminals were designated for short-term use, limiting sessions to a maximum of 10 minutes per user. While the exact installation timeline remained unspecified, the university advised anyone who had accessed library workstations within the preceding 12 months to assume potential exposure. The discovery prompted immediate warnings to students and staff, emphasizing the risk of captured credentials and sensitive data. No information was disclosed regarding the total number of affected devices, the duration of the keyloggers' presence, or the method of detection.

Cyber Incident Image

The incident posed risks primarily to individuals who had entered passwords or financial information on the compromised terminals during the exposure window. Concordia specifically highlighted concerns about online banking credentials due to the potential for financial fraud. In response, the institution directed affected users to change passwords associated with university accounts and any other services accessed via the workstations, particularly recommending updates to banking credentials as a precautionary measure. The university’s public advisory did not confirm whether unauthorized data collection had occurred but treated the discovery as evidence of a deliberate attempt to harvest information. No additional technical containment measures, forensic findings, or perpetrator details were disclosed in the initial notification. The incident underscored vulnerabilities in publicly accessible computing infrastructure while leaving key operational questions about the breach’s scope and origins unanswered in the available public reporting.

Sources
Sources available to members
1 source