Menu
Browse

Cyber Incident Victim: College of Eastern Idaho

Date:

Jun 2025

Location:

United States of America

Summary

The College of Eastern Idaho experienced a malware attack introduced into its network environment via a student's personal laptop accessing an external website. This prompted the institution to proactively shut down its network systems as a precaution. The attack subsequently escalated into a Trojan horse incident targeting college infrastructure. While working with cybersecurity experts to eliminate the malware and restore functionality, the college found no evidence of a student or staff data breach. Contingency plans are enabling normal summer course operations despite the ongoing restoration efforts, which lack a definitive completion timeline.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

The College of Eastern Idaho (CEI) experienced a cyberattack originating last week when a student used a personal laptop to access an external website. This action introduced malware into the college's network environment. In response to this initial intrusion, CEI proactively shut down its network systems as a precautionary measure. While the CEI Information Technology team worked to contain and monitor this threat, the malicious actor escalated the attack. The attackers launched a Trojan horse attack against the college's systems. CEI responded quickly to this escalation by shutting down its systems completely to prevent further intrusion and protect the integrity of college data and infrastructure. The college has not yet fully eliminated the malware from its network as of the announcement date. Despite the ongoing incident, CEI stated it has found no evidence indicating a breach of student or staff data occurred.

Cyber Incident Image

CEI President Lori Barber emphasized that the safety and security of students, faculty, and institutional data was the college's top priority. The college is working closely with cybersecurity experts and following all appropriate protocols and regulatory guidelines to fully eliminate the malware and restore system functionality. CEI activated contingency plans designed to ensure academic continuity, allowing summer courses to run normally despite the network disruption. The college remains committed to supporting students and staff throughout the incident response and recovery process. CEI does not have a definitive timeline for when full network functionality will be restored. The college released this information publicly on Monday, June 1st, 2025, confirming the attack and its ongoing response efforts.

Sources
Sources available to members
1 source