CSIDB logo
Incident

Bar Ilan University

Incident posture

Attack window
Aug 2021
Location
Israel
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
Bar Ilan University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Bar Ilan University, prompting its IT department to issue an urgent internal warning about ongoing data erasure and instruct staff to immediately shut down computers to mitigate damage. The incident caused operational disruption as systems were compromised during active data destruction efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 15, 2021, Bar Ilan University in Israel experienced a disruptive cyberattack that prompted urgent operational responses. The university's IT department confirmed the active incident in an internal email circulated that Sunday, explicitly stating that data deletion was occurring in real time during the attack. This communication directed all staff members to immediately power down their computers to mitigate further damage, indicating a live threat to university systems. The attack unfolded during standard university operations, though the specific initial intrusion vector and precise time of compromise were not publicly disclosed. No external threat actor claimed responsibility in the immediate aftermath, and the university did not specify whether ransomware, data exfiltration, or another attack methodology was involved.

The incident caused significant disruption by forcing an abrupt shutdown of workstations across the institution, though the full scope of affected systems remained unclear from available reports. The IT department’s directive prioritized containment through isolation of devices, suggesting concerns about lateral movement within the network. No details emerged regarding the type or sensitivity of data targeted for erasure, nor were teaching, research, or administrative systems explicitly identified as compromised. The university did not release information about pre-existing security measures, detection methods, or subsequent forensic investigations. Recovery timelines and the ultimate success of containment efforts were not documented in the immediate public reporting, leaving the operational and financial consequences undefined at the time of disclosure.

Sources

Sources available to members: 1 source.

CSIDB