CSIDB logo
Incident

University of Kentucky

Incident posture

Attack window
Aug 2013
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 15:59

Linked entities

Victim
University of Kentucky
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2013
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A web server used by California State University's East Bay campus to store employment transaction records and some extended learning course information was breached by an unknown unauthorized person using malicious software, resulting in the copying of a data file containing the full names, addresses, and Social Security numbers of more than 6,000 individuals. The birth dates of over 500 of those individuals were also included in the exposed file. The intrusion went undetected for nearly a year before being discovered by the university's information security team, after which officials disclosed the incident and submitted a notification letter template to California's Attorney General.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

California State University disclosed a data security breach affecting a web server used to store personal employee information. The incident involved the university's East Bay campus, where the information security team discovered the unauthorized intrusion during an internal review. According to officials, the security breach occurred on August 23, 2013, when an unknown individual broke into a university web server used to store various employment transaction records and some extended learning course information. The breach went undiscovered for nearly a year, with detection occurring on August 11, 2014, meaning the unauthorized access persisted in the environment for approximately eleven months before being identified by the campus security team. During this extended window, the attacker had the ability to copy sensitive data from the compromised server.

The breach involved a malicious software tool that allowed an unauthorized person to copy a data file containing the full names, addresses, and Social Security numbers of 6,036 individuals. Additionally, the birth dates of 508 individuals were included in the compromised data file. This combination of personally identifiable information, including Social Security numbers, exposed affected individuals to significant risks of identity theft and financial fraud. The data file appears to have been specifically targeted for its concentration of sensitive employee and learner records, suggesting the attacker understood the value of the stored information. The scale of the breach, affecting thousands of individuals whose employment records were stored on the server, indicated a substantial impact on the campus community and potentially other individuals associated with extended learning programs.

Following the discovery on August 11, 2014, the university launched an internal investigation to determine the scope and nature of the intrusion. Officials disclosed the breach publicly in early September 2014, with the public report appearing on September 6, 2014. A template of the notification letter sent to affected employees was submitted to California's Attorney General, demonstrating compliance with state breach notification requirements. The notification process was designed to inform approximately 6,036 individuals whose full names, addresses, and Social Security numbers had been compromised, as well as the 508 individuals whose birth dates were additionally included in the exposed data file. The breach notification was conducted as a regulatory and remedial action to alert affected parties to the potential exposure of their personal information and to provide them with information necessary to protect themselves against potential misuse of their data.

Sources

Sources available to members: 1 source.

CSIDB