CSIDB logo
Incident

Abertay University

Incident posture

Attack window
Aug 2013
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 16:01

Linked entities

Victim
Abertay University
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2013
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A malicious software tool was used by an unauthorized person to breach a web server storing employment records at California State University's East Bay campus, going undetected for nearly a year before discovery. The resulting data file exposure included the full names, addresses, and Social Security numbers of 6,036 individuals, along with the birth dates of 508 of those affected. The institution subsequently notified impacted employees and filed a breach notification letter template with the California Attorney General's office.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 6, 2014, California State University disclosed a data breach affecting the East Bay campus that had gone undiscovered for nearly a year. According to officials, the university's East Bay information security team discovered the breach on August 11, 2014, during a review that traced the intrusion back to August 23, 2013. The lengthy gap between the initial compromise and its detection meant that personal information stored on the affected web server remained exposed to unauthorized parties for almost twelve months before the institution became aware of the problem. Dennis Culver's report, republished on the DataBreaches.net site, indicated that the breach involved a university web server used to store various employment transaction records along with some extended learning course information, making the compromised system a repository for both human resources data and academic administrative records associated with non-degree or continuing education offerings.

The attacker gained entry through a malicious software tool that enabled an unauthorized person to copy a data file containing the full names, addresses, and Social Security numbers of 6,036 individuals. Beyond the core identifying information, the birth dates of 508 of those individuals were also present on the same data file, adding a further layer of sensitive personal data to the exposure. The combination of names, addresses, Social Security numbers, and dates of birth created a particularly high-risk profile for affected individuals, as these data elements together can be used for identity verification, account creation, and various forms of financial fraud. Because the breach was not discovered for approximately a year, the copied data had a prolonged window during which it could have been exploited by the unknown intruder or any party to whom the intruder might have provided access. University officials did not publicly identify the attacker, and the mechanism by which the malicious software tool was initially deployed on the server was not described in the disclosure reporting available.

Following the discovery of the breach on August 11, 2014, the university's information security team and institutional leadership conducted a subsequent investigation to determine the scope and nature of the compromise. That investigation confirmed that an unknown person had broken into the university web server and that personal employee information had been copied off the system. The university prepared and submitted a notification letter to California's Attorney General, with a template of that letter made publicly viewable as a PDF, providing transparency about the form of communication being sent to those impacted. The disclosure to the Attorney General was a procedural step required under California law for breaches involving significant quantities of personal information, and the act of filing the template indicated that the university was undertaking a formal notification process for the affected individuals rather than handling the matter solely through internal channels.

The direct impact of the incident centered on the 6,036 individuals whose full names, addresses, and Social Security numbers were contained in the copied data file, with a subset of 508 of those individuals also having their birth dates exposed. Because the compromised records were described as employment transaction records, the affected population was primarily composed of individuals connected to the university's employment processes, such as current and former employees and possibly applicants or others whose records were retained in human resources systems. The exposure of extended learning course information on the same server suggested that data tied to continuing education participants may also have been accessible, though the reported file that was copied focused on the personal identifying details of the larger group. The university's response to the disclosure included public communication through the news media and regulatory channels, the submission of a notification template to the state Attorney General, and the sharing of the broader incident details through the SFBay coverage referenced in the original reporting.

The detection of the breach only after nearly a year underscored the challenge of identifying persistent compromises on web servers that store administrative and personnel records, particularly when the intrusion method relied on a malicious software tool capable of quietly extracting files. By the time the breach was discovered and disclosed in August and September of 2014, the copied data had already been outside the university's control for an extended period, and the institution could only begin notifying affected individuals and relevant authorities at that point. The reporting available did not detail specific containment actions taken after discovery, nor did it describe any subsequent legal proceedings, credit monitoring offers, or other remediation measures extended to the affected population, leaving the post-disclosure response largely framed by the notification process and the public disclosure itself.

Sources

Sources available to members: 1 source.

CSIDB