The University of California, Berkeley (UC Berkeley) suffered a data breach linked to a cyberattack against Accellion, a third-party service contracted by UC for secure file transfers. The “University of California Office of the President (UCOP) confirmed that attackers exploited a vulnerability in Accellion to gain access to its data,” according to one report.
UC Berkeley employees received an email from an unknown source claiming possession of stolen personal data. The email also contained a link that showed a sample of UC employees’ personal details. The attackers threatened to expose sensitive personal information on the dark web unless demands were met. This incident reinforced the importance of robust cybersecurity measures to protect university systems and data, even from contracted third-party service providers.
The attack originated from a security flaw in Accellion’s legacy File Transfer Appliance (FTA), a product used by various institutions to share files securely. According to another report, cybercriminals exploited this vulnerability to gain unauthorized access to confidential data across multiple organizations, including UC Berkeley.
Following the breach, the university worked with local and federal law enforcement and third-party vendors to investigate the incident, assess the compromised information, and limit the release of stolen information. The entire UC community was also provided with a one-year complimentary credit monitoring and identity theft protection.
How to Protect Yourself from Cyber Threats:
Universities remain a prime target for cybercriminals due to the wealth of sensitive data they store. By staying vigilant and implementing strong cybersecurity practices in your daily routine, you help protect UC Riverside from malicious cyber threats.