Shostack + Friends Blog Archive


University of Colorado at Colorado Springs, 2500 employees, SSNs, "virus"

Looks like a worm hit a personnel department PC.
From the Colorado Springs Gazette:

Personal information on about 2,500 current and former employees at the University of Colorado at Colorado Springs has been compromised by someone who hacked into a computer and infected it with a virus.
Names, Social Security numbers, birth dates and addresses for employees dating back to 2004 were accessed without authorization Friday, the university said Tuesday.
Obtaining that information did not appear to be the reason for the attack on the computer in the Personnel Department, officials said. They still urged faculty and staff members to notify credit reporting bureaus of the breach and take other precautions against ID theft.