Data leak

Stanford University / Maine AG / BleepingComputer

πŸ“… 2023-05-12 🦠 Akira
Primary Source β†—

Incident Details

Akira ransomware group breached Stanford University’s Department of Public Safety (SUDPS) network between May 12 and September 27 2023. Stanford disclosed the incident on October 27 2023 after the Akira gang published the stolen data (430 GB) on their leak site. The breach affected 27,000 individuals whose personal information was stored on the SUDPS network, including Social Security numbers, government IDs, and financial information. Victims included current and former students, staff, and applicants to the SUDPS. The Akira group specifically targeted the campus public safety department rather than central IT systems. Stanford offered 24 months of credit monitoring to affected individuals.

Technical Details

Initial Attack Vector
CWE-506: Embedded Malicious Code (Akira ransomware targeting Stanford's Department of Public Safety network)
Malware Family
Akira

Timeline

  1. 2023-05-12 Breach occurred
  2. 2023-10-27 Publicly disclosed
  3. 2023-10-27 Customers notified