Menu
Browse

Cyber Incident Victim: University of California, Davis

Date:

Mar 2021

Location:

United States of America

Summary

The University of California experienced a cybersecurity attack exploiting a vulnerability in Accellion's file transfer service, which also impacted other universities, government agencies, and private companies nationwide. An unauthorized actor copied and transferred institutional files, prompting immediate containment measures, federal law enforcement reporting, and an ongoing investigation to assess data exposure. While the breach was confined to the Accellion system without compromising broader networks, attackers published screenshots of personal information online. The institution committed to notifying affected individuals upon completing its review of potentially leaked data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In late March 2021, the University of California system, including UC Davis, was targeted in a nationwide cyberattack exploiting vulnerabilities in Accellion’s secure file transfer service. The attackers gained unauthorized access to UC’s Accellion instance, copying and transferring institutional files by leveraging a flaw in the vendor’s software. UC officials confirmed the breach affected multiple entities beyond higher education, including government agencies and private companies. Upon discovering the incident, UC immediately notified federal law enforcement agencies, initiated containment protocols to isolate the compromise, and launched an internal investigation. Preliminary analysis indicated the attack was confined to the Accellion file transfer system, with no evidence of lateral movement into core UC networks or other university systems. The investigation focused on identifying the scope of data exfiltrated from Accellion’s platform, which UC utilized for secure document sharing.

Cyber Incident Image

UC initiated a comprehensive review of potentially compromised files to determine the nature of stolen data and affected individuals. While the forensic examination was ongoing, attackers publicly released screenshots containing personal information purportedly obtained during the breach. UC committed to notifying community members if their data was confirmed among the leaked materials, though specific details regarding data categories or victim counts remained undisclosed pending the investigation’s completion. The university acknowledged the likelihood of sensitive information exposure but did not confirm particular data elements beyond the screenshots. Response efforts prioritized containment through system isolation, collaboration with law enforcement, and preparatory measures for individual notifications once impacted parties were definitively identified. No operational disruptions to university functions beyond the Accellion service were reported.

Sources
Sources available to members
1 source