TechCrunch News 11月06日 00:13
宾夕法尼亚大学确认遭黑客攻击,数据被盗
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

宾夕法尼亚大学证实,上周发生的数据泄露事件中,黑客确实窃取了大学数据。此次事件导致校友及相关人士收到来自官方大学邮箱的可疑邮件。黑客声称已获取大量敏感信息,并以此威胁大学。大学最初否认,后承认部分信息系统遭到入侵,并已采取措施阻止进一步的未授权访问。此次攻击疑似通过社会工程学手段,利用MFA豁免漏洞进行。受影响的个人信息将按法律规定收到通知,但具体细节尚未公布。此次事件与哥伦比亚大学近期发生的黑客攻击事件在动机上可能存在关联,均指向对平权行动政策的不满。

🔒 **大学数据泄露确认**:宾夕法尼亚大学已正式确认,上周发生的数据泄露事件中,黑客确实成功窃取了大学的数据。此次事件并非虚假信息,黑客的声明得到了校方的证实,给大学的声誉和数据安全带来了严重挑战。

📧 **官方邮箱被滥用与信息威胁**:黑客利用被盗的大学数据,通过官方的`@upenn.edu`邮箱地址向校友和教职员工发送了包含威胁和勒索信息的邮件。这些邮件内容提及违反联邦法律,并威胁将公开敏感信息,凸显了数据泄露的严重性。

🎣 **社会工程学攻击与MFA漏洞**:大学方面透露,此次攻击是通过社会工程学手段实现的,即诱骗内部人员泄露敏感信息。同时,有消息指出,部分高级官员可能享有豁免多因素认证(MFA)的特权,这可能为黑客提供了可乘之机。

⚖️ **法律合规与后续通知**:宾夕法尼亚大学表示将遵守法律规定,通知所有个人信息被黑客访问的受害者。然而,关于通知的具体时间、受影响人数以及被访问信息的详细范围,大学尚未对外公布。

⚖️ **与平权行动政策的潜在关联**:此次宾夕法尼亚大学的黑客攻击事件,与近期哥伦比亚大学发生的类似事件,在动机上存在潜在联系。黑客在邮件中表达了对大学招生和录用政策(如平权行动、捐赠者子女入学等)的不满,暗示其行为可能与此有关。

The University of Pennsylvania confirmed on Tuesday that a hacker stole university data as part of last week’s data breach, during which alumni and other affiliates received suspicious emails from official university email addresses.

“We got hacked,” the message from the hackers read. “We love breaking federal laws like FERPA (all your data will be leaked),” the message added. “Please stop giving us money.”

While Penn initially told TechCrunch that the email was “fraudulent,” the university has now confirmed the hacker’s claim that data was taken during the breach.

“On October 31, Penn discovered that a select group of information systems related to Penn’s development and alumni activities had been compromised,” the university wrote in a statement, which was emailed to alumni and shared online. “Penn’s staff rapidly locked down the systems and prevented further unauthorized access; however, not before an offensive and fraudulent email was sent to our community and information was taken by the attacker.”

(Disclosure: As an alumna and former employee of the university, the hackers sent the message to my personal email three times, each coming from different official @upenn.edu email addresses, including one from a senior Penn staff member.)

A partially redacted email sent by hackers from a university of Pennsylvania email address.Image Credits:TechCrunch (Screenshot)

The university said that the breach occurred due to a social engineering attack, a hacking technique in which individuals are tricked into handing over sensitive information like log-in credentials, perhaps through phishing or a phone call.

A Penn employee, who we are not naming as they were not authorized to speak to the press, told TechCrunch that the university requires students, staff, and alumni to use multi-factor authentication (MFA) on their accounts as a security measure; however, the employee said that some high-ranking officials were granted exemptions to MFA requirements.

TechCrunch asked Penn about these alleged MFA exceptions, and if the university could provide a percentage of MFA adoption among staff. Penn spokesperson Ron Ozio declined to comment to TechCrunch beyond Penn’s official data incident page.

As required by law, Penn said it will contact individuals whose personal information was accessed by hackers. The university has not said when these notifications will occur, how many people are affected, or what information was accessed.

The Daily Pennsylvanian reports that the alleged Penn hacker claimed to have taken documents relating to university donors, bank transaction receipts, and personally identifiable information. The hacker said they were financially motivated.

Earlier this year, hackers breached Columbia University, accessing sensitive information about around 870,000 students and applicants, including their Social Security numbers and citizenship status.

Both the Penn and Columbia hacks appear motivated by discontent with affirmative action policies. In the email that the Penn hacker sent to the university community, the hacker wrote, “We hire and admit morons because we love legacies, donors, and unqualified affirmative action admits.” Meanwhile, the Columbia hacker told Bloomberg that they sought to access data from the university to investigate its affirmative action practices.

If you have more information about the Penn hack, you can contact Amanda Silberling securely on Signal at @amanda.100, or by email, from a non-work device.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

宾夕法尼亚大学 数据泄露 黑客攻击 网络安全 社会工程学 MFA 平权行动 University of Pennsylvania Data Breach Hacker Attack Cybersecurity Social Engineering MFA Affirmative Action
相关文章