Data leak

Penn State University Computer Science Network Breach β€” APT (18,000 Individuals)

πŸ“… 2012-09-01
Primary Source β†—

Incident Details

In May 2015, Pennsylvania State University disclosed that its College of Engineering computer network had been compromised by two separate sophisticated cyberattacks. One was attributed to state-sponsored actors based in China. The FBI had been investigating since at least November 2014 and notified Penn State. The university took the College of Engineering network offline on May 15, 2015, to contain the intrusion and remediate. One attack had reportedly been present since approximately September 2012 β€” meaning the attacker had persistent access for over two years. Approximately 18,000 individuals (students, staff, and faculty) had data potentially exposed, including Social Security numbers and other personal information. The targeting of an engineering school with significant defense-related research contracts made this incident notable β€” the suspected motive was theft of technical research and intellectual property rather than financial fraud. Penn State brought in cybersecurity firm FireEye/Mandiant to assist with forensics and remediation. The incident highlighted the vulnerability of university research networks, which combine open academic culture with sensitive government-funded research.

Technical Details

Initial Attack Vector
Two separate nation-state APT intrusions: one attributed to China-based actors (active from approximately September 2012) and one from an unattributed threat actor; the attackers used sophisticated malware to gain persistent access to Penn State's College of Engineering network

Timeline

  1. 2012-09-01 Breach occurred
  2. 2015-05-15 Publicly disclosed
  3. 2015-05-15 Customers notified