CSIDB logo
Incident

University of Connecticut

Incident posture

Attack window
Aug 2013
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 15:59

Linked entities

Victim
University of Connecticut
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2013
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A web server at California State University's East Bay campus was compromised by an unauthorized person using malicious software, allowing the copying of a data file containing personal information of over six thousand individuals. The breach affected full names, addresses, and Social Security numbers of 6,036 people, with the birth dates of 508 individuals also included in the exposed data file. The university's information security team discovered the incident roughly a year after it occurred, and the compromised server had been used to store various employment transaction records and some extended learning course information. Notification letters were subsequently sent to affected employees, with a template of the notification submitted to California's Attorney General.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Note: The provided source article concerns California State University, East Bay (CSU East Bay), not the University of Connecticut. No source material describing an incident involving the University of Connecticut is available in the prompt. To avoid fabricating details about an unrelated institution, a narrative cannot be produced for the requested subject. The single available article is summarized below for completeness, but it does not match the named entity in the task.

California State University's East Bay campus disclosed on September 6, 2014 that a data breach on one of its web servers had gone undetected for nearly a year. University officials stated that the security breach occurred on August 23, 2013, but was not discovered until August 11, 2014. Once identified, an investigation revealed that an unknown actor had broken into a university web server that was used to store various employment transaction records as well as some extended learning course information. A malicious software tool was used by the unauthorized individual to copy a data file containing personal information from the server. The compromised data file held the full names, addresses, and Social Security numbers of 6,036 individuals, and additionally included the birth dates of 508 of those individuals. After confirming the scope of the exposure, the university prepared a template notification letter for affected employees and submitted it to the California Attorney General's office for public review.

Sources

Sources available to members: 1 source.

CSIDB