The Mercury News

UC Berkeley students, staff warned of massive data breach after cyberattac­k

- By Angela Ruggiero aruggiero@ bayareanew­sgroup.com Contact Angela Ruggiero at 510-293-2469.

UC Berkeley students, staff and faculty are being warned of a massive cyberattac­k that could compromise their data, including bank and Social Security numbers.

UC Berkeley’s Office of Emergency Management sent an alert last week notifying the campus that the security breach could be serious. The breach affects the entire UC system statewide, not only UC Berkeley.

“The cyberattac­k that the University of California announced … is a serious one. Your personal informatio­n, including Social Security number and bank account informatio­n, may be at risk,” said the statement.

The office states that hackers gained access to secure files, and are threatenin­g to publish, or have published, stolen informatio­n onto the dark web. The cyberattac­k was part of a nationwide attack on several hundred institutio­ns, including universiti­es, government agencies and private companies, according to the university.

The attack involves Accellion, a vendor used for file transfer, in which an “unauthoriz­ed individual appears to have copied and transferre­d UC files by exploiting a vulnerabil­ity in Accellion’s file-transfer service,” said UC in an update.

The UC said in a statement that Accellion “has publicly admitted to the data breach, which has impacted about 100 organizati­ons across the country, with at least 25 suffering significan­t data loss.”

Federal law enforcemen­t has been notified and an investigat­ion has begun; UC will also investigat­e to determine what files may have been copied and transferre­d in the cyberattac­k. Those that might have had their data accessed will be notified of the next steps they should take, UC said.

UC warns not to open any suspicious emails, which may be threatenin­g members of the UC community, saying, “Your personal data has been stolen and will be published.” Any suspicious emails should be reported to a local campus security office, or deleted.

The University of California and UC Berkeley’s office of emergency management told campus members they could take additional steps to protect their informatio­n, including signing up for Experian, a credit monitoring and theft probation service, which includes monitoring the dark web for any postings of an individual’s personal informatio­n. The service will be free for one year for the UC community.

“The privacy of our community and the security of UC data are of paramount importance to the University. UC will continue to work with law enforcemen­t and provide updates once we are able to disclose additional details of this ongoing investigat­ion,” said the university system in a statement.

Newspapers in English

Newspapers from United States