Data leak
University of Maryland Data Breach β 310,000 Records
Primary Source βIncident Details
On February 18, 2014, the University of Maryland suffered a data breach in which attackers accessed a database containing records for 309,079 faculty, staff, and students who had been issued a university ID since 1998. The university disclosed the breach just one day later, on February 19 β an unusually rapid disclosure. Exposed data included names, Social Security numbers, dates of birth, and university ID numbers. No financial or academic records were included. University President Wallace Loh disclosed the breach directly via email to the university community and issued a public statement. The breach prompted the university to bring in outside cybersecurity experts and conduct a security audit. The university offered credit monitoring to those affected. Maryland Governor Martin O’Malley publicly commented on the breach, which received significant media attention as an example of the higher education sector’s vulnerability to data theft. The rapid, transparent disclosure was widely praised as a model for breach response.
Technical Details
- Initial Attack Vector
- Attackers gained unauthorized access to a University of Maryland database server containing records for all faculty, staff, and students who had been issued a university ID; the specific technical attack vector was not fully disclosed but involved unauthorized access to a records database
Timeline
- 2014-02-18 Breach occurred
- 2014-02-19 Publicly disclosed
- 2014-02-19 Customers notified