Menu
Browse

Cyber Incident Victim: Wichita State University

Date:

Dec 2019

Location:

United States of America

Summary

Wichita State University experienced a cybersecurity incident involving unauthorized access to a server hosting student and employee web portals. An attacker compromised the server during a brief period, accessing a historical database containing names, email addresses, dates of birth, and Social Security numbers belonging to 1,762 Iowa residents. The institution secured the affected server, initiated a forensic investigation, and confirmed the scope of exposed data approximately one month after detecting the breach. Notification letters were subsequently mailed to impacted individuals, and the university implemented staff re-education as part of enhanced security measures.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Wichita State University experienced unauthorized access to a computer server used for student and employee web portals between December 3 and December 5, 2019. The institution discovered this security incident in December 2019 and immediately secured the compromised server. They engaged a computer forensic firm to investigate the breach's scope and impact. The forensic investigation confirmed the attacker's access window spanned three days in early December. While the specific intrusion method wasn't publicly disclosed, the university's subsequent staff re-education efforts suggest potential human factors may have contributed to the breach.

Cyber Incident Image

The investigation revealed that the accessed server contained a historical database with sensitive personal information. On January 13, 2020, WSU confirmed the compromised data included names, email addresses, dates of birth, and Social Security numbers belonging to 1,762 Iowa residents. Notification letters were mailed to affected individuals beginning March 6, 2020, in compliance with Iowa's breach notification laws. This incident marked the second significant cybersecurity event for the university in 2019, following an earlier phishing attack that had compromised employee paychecks. The breach response involved coordinated efforts between university IT staff, external legal counsel, and forensic investigators to contain the incident and assess its impact.

Sources
Sources available to members
1 source