Menu
Browse

Cyber Incident Victim: University of Basel

Date:

Oct 2020

Location:

Switzerland

Summary

Hackers conducted spear-phishing attacks targeting multiple Swiss universities, successfully compromising the University of Basel's systems by stealing employee credentials. The attackers diverted salary payments to fraudulent accounts, resulting in a six-figure financial theft with portions transferred abroad. While the University of Zurich thwarted similar attempts through employee vigilance, the breach prompted a sector-wide alert from the national universities' umbrella organization to bolster defenses against such threats.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early October 2020, threat actors conducted a financial theft campaign targeting multiple Swiss universities, including the University of Basel. The attackers employed spear-phishing techniques against university employees to harvest their login credentials. After successfully compromising these credentials, the hackers infiltrated university systems responsible for processing salary payments. They specifically manipulated payment instructions by altering beneficiary bank account details to divert funds to accounts under their control. The Basel public prosecutor's office confirmed the unauthorized system access and fraudulent transaction modifications at affected institutions. While the University of Basel suffered financial losses, the University of Zurich successfully identified and neutralized similar phishing attempts before any funds were stolen.

Cyber Incident Image

The attack resulted in the theft of a six-figure sum from compromised universities, with stolen funds rapidly transferred to foreign bank accounts. Swissuniversities, the national higher education umbrella organization, issued warnings to member institutions following the discovery of the breaches. Martina Weiss, Secretary General of the Rectors' Conference, publicly acknowledged multiple universities were impacted. The incident prompted heightened vigilance across Swiss academic institutions regarding financial transaction processes. No technical details about the compromised systems or specific forensic findings were disclosed publicly beyond the confirmation of phishing-based initial access and subsequent payment redirection. The Basel prosecutor's investigation remained active at the time of reporting, focusing on the international movement of misappropriated funds.

Sources
Sources available to members
1 source