CSIDB logo
Incident

Universiteit van Amsterdam

Incident posture

Attack window
Feb 2021
Location
Netherlands
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
Universiteit van Amsterdam
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack compromised the ICT environments of the University of Amsterdam and Hogeschool van Amsterdam, with unauthorized access by unknown third parties detected by the Security and Operations Center. The institutions implemented measures to mitigate consequences and maintain continuity of education and research operations, including precautionary shutdowns of multiple systems to contain the incident.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

6 techniques

Description

On or around February 17, 2021, the University of Amsterdam (UvA) and the Hogeschool van Amsterdam (HvA) experienced a cybersecurity incident involving unauthorized access to their ICT environments. The breach was identified by the institutions' Security and Operations Center, which detected that unknown third parties had infiltrated their systems. Both educational organizations implemented immediate containment measures, including disabling multiple ICT systems as a precautionary step to prevent further unauthorized activity. The primary objective of these actions was to minimize operational disruptions while safeguarding ongoing educational and research activities. No specific details were disclosed regarding the exact entry vectors used by the attackers or the duration of unauthorized access prior to detection.

The coordinated response focused on maintaining academic continuity despite system disruptions caused by the protective shutdowns. Neither institution released information about the scope of compromised data or whether student, staff, or research information was accessed or exfiltrated. Operational impacts included the temporary unavailability of disabled systems, though specific affected applications or services were not detailed publicly. Both universities emphasized their efforts to restore normal operations while investigating the incident, but did not disclose remediation timelines or whether law enforcement agencies were involved. The incident marked a significant operational challenge for Amsterdam's higher education sector, requiring resource reallocation to manage both cybersecurity containment and academic continuity obligations simultaneously.

Sources

Sources available to members: 1 source.

CSIDB