Hackers breach UC Berkeley computer database
SAN FRANCISCO — University of California, Berkeley, officials said Friday that hackers infiltrated restricted computer databases, putting at risk health and other personal information on 160,000 students, alumni and others.
The university said data include Social Security numbers, birth dates, health insurance information and some medical records dating back to 1999. Personal medical records — such as patient diagnoses, treatments and therapies — were not compromised, officials said.
The databases also included personal information of parents, spouses and Mills College students who used or were eligible for Berkeley’s health services.
In all, 97,000 Social Security numbers were stolen, said Shelton Waggener, UC Berkeley’s associate vice chancellor for information technology and its chief information officer.
Social Security numbers can be used by identity thieves to access a person’s current credit history, or bank and credit card accounts, according to the California Office of Privacy Protection. The numbers can also be used to open new bank and credit accounts, or even get a driver’s license in the victim’s name, privacy-protection officials warn.
The school has identified 160,000 total names in the database and contacted everyone regardless of whether their Social Security number also was compromised.
The server breach occurred on Oct. 6, 2008, and lasted until April 9, when campus staff performing routine maintenance found messages the school said were left by the hackers.
“The indications are that the hackers left messages to the system administrator taunting the system administrator that they had broken in,” Waggener said. “It’s a common hacker approach for identifying themselves.”
The school said it had traced the hackers’ computers to a number of overseas locations, including China, and turned that information over to the FBI and campus police. An outside Internet security firm has also been hired to conduct an audit of the school’s systems and its information security measures.
Although the breach was discovered April 9, former and current students did not receive e-mail notification of the hacks until Friday morning. The university said it took forensic technology experts until April 21 to figure out which databases were hacked.
“Since then a team of more than 20 people from across the campus have been working seven days a week to determine the exact scope and nature of the breach,” the school said.
It established a Web site at datatheft.berkeley.edu to answer questions about the incident.
Graduate student Kate Monroe, 27, said she was taking the school’s warning seriously and planned to have a free fraud alert added to her credit report.
“My mom has dealt with identity theft and it’s no joke,” Monroe said. “Getting her identity cleaned up has been nearly impossible.”
The school said Friday it had not received any reports of identity theft from any students who were notified.
In March 2005, a thief walked into a UC Berkeley office and swiped a computer laptop containing personal information on nearly 100,000 alumni, graduate students and past applicants. Officials said that laptop was recovered before any personal information was breached.
Six months earlier, a computer hacker gained access to UC Berkeley research being done for the state Department of Social Services. Those files contained personal information of about 600,000 people.
On the Net:
datatheft.berkeley.edu
Related News
Pa. police say man charged with drunken driving tried to steal tow truck to retrieve vehicleSeptember 14th, 2009 Police say DUI suspect tried to steal tow truckBETHLEHEM, Pa. — Police in eastern Pennsylvania said a man charged with drunken driving faces more charges after allegedly trying to steal a tow truck a few hours later to retrieve his impounded vehicle.
Police say man wearing only Speedo-style suit tried to steal vehicles, stole items out of themAugust 23rd, 2009 Police: Man wearing Speedo tried to steal vehiclesEAST HARTFORD, Conn. — A burglary suspect wearing only a Speedo-style swimsuit has been arrested in Connecticut after a police dog tracked him down and bit him on the leg.
Man charged with stealing 130M credit card numbers in record identity theftAugust 18th, 2009 Prosecutors say man stole 130M credit card numbersWASHINGTON — A former government informant known online as "soupnazi" stole information from 130 million credit and debit card accounts in what federal prosecutors are calling the largest case of identity theft yet. Prosecutors said Monday that Albert Gonzalez, 28, of Miami broke his own record for identity theft, though his exploits ended when he went to jail on charges stemming from an earlier case involving 40 million accounts.
Man charged with trying to steal 130M credit card numbers in record credit card data theftAugust 17th, 2009 Gov't: Man tried to steal 130M credit card numbersWASHINGTON — Federal prosecutors on Monday charged a Miami man with the largest case of credit and debit card data theft ever in the United States, accusing the one-time government informant of plotting to swipe 130 million accounts on top of 40 million he stole previously. Albert Gonzalez, 28, broke his own record for identity theft by hacking into retail networks, according to prosecutors, though they say his illicit computer exploits ended when he went to jail on charges stemming from an earlier case.
SKorean police: Hackers extracted data from virus-contaminated computers in cyberattacksJuly 14th, 2009 SKorean police: Hackers extracted data in attacksSEOUL, South Korea — Hackers extracted lists of files from computers that they contaminated with the virus that triggered cyberattacks last week in the United States and South Korea, police in Seoul said Tuesday. The attacks, in which floods of computers tried to connect to a single Web site at the same time to overwhelm the server, caused outages on prominent government-run sites in both countries.
Hackers post pro-Iranian message on Oregon University System home pageJune 24th, 2009 Hackers invade Oregon university system computersPORTLAND, Ore. — Hackers got into the computers of the Oregon University System and posted a message telling President Barack Obama to mind his own business and not to comment on the disputed Iranian election.
Hackers post message supporting Iranian regime on Oregon University System home pageJune 24th, 2009 Pro-Iranian regime hackers invade Oregon computersPORTLAND, Ore. — Hackers defaced the home page of the Oregon University System, posting a caustic message telling President Barack Obama to mind his own business and stop talking about the disputed Iranian election.
Cornell probes theft of school computer with personal information; thousands could be affectedJune 23rd, 2009 Cornell probes loss of personal informationITHACA, N.Y. — Cornell University officials are investigating the theft of a school computer that may have compromised the personal information of thousands of current and former students, faculty and staff.
Va. gov: State won't pay $10 million ransom to hacker who accessed prescription recordsMay 8th, 2009 Va. gov says state won't pay hacker ransomRICHMOND, Va. — Virginia Gov.
LexisNexis warns 32,000 people their personal data may have been viewed by former customersMay 2nd, 2009 LexisNexis warns 32,000 people about data breachNEW YORK — The LexisNexis online information service told 32,000 people on Friday that their personal information may have been improperly accessed by former customers in a credit card fraud scheme that postal officials said had bilked hundreds. "I am writing to inform you that sensitive, personally identifiable information about you may have been viewed by a few individuals who should not have access to such information," said the letter mailed Friday to people whose information is in LexisNexis databases.
Ark. men arrested after allegedly trying to steal county pickup truck that wouldn't runApril 28th, 2009 Men try to steal pickup truck that doesn't runPINE BLUFF, Ark. — Even though the truck wouldn't run, it was still a crime to try to steal it.
Red Sox speedster Jacoby Ellsbury steals home against Andy Pettitte of New York YankeesApril 27th, 2009 Boston speedster Ellsbury steals homeBOSTON — Jacoby Ellsbury became the first player to steal home this season, doing it for the Boston Red Sox against Andy Pettitte of the New York Yankees. J.D. Drew was at bat with the bases loaded in the fifth inning after Kevin Youkilis was walked intentionally on Sunday night.
Commissioner says international hackers target NYPD computers, but they're foiledApril 23rd, 2009 NYPD computers targeted by international hackersNEW YORK — New York Police Commissioner Raymond Kelly says international hackers try at least 70,000 times a day to gain unauthorized entry into the computer system of the nation's largest police force. But he said Wednesday all the attempts have failed because of a strong protection system that prevents security breaches.
US firm reveals possibly biggest data breach so farJanuary 20th, 2009 SAN FRANCISCO - Credit-card processing company Heartland has revealed what is possibly the greatest data breach in history, prompting widespread speculation that it waited until the inauguration of President Barack Obama to release the news. The company serves some 250,000 businesses and processes an estimated 100 million transactions a month.
Paris Hilton's website hackedJanuary 13th, 2009 LONDON - Socialite heiress Paris Hilton has been targeted by cyber thieves trying to steal personal information of her fans through her website. The hackers infected her website ParisHilton.com with a virus, which sucks personal details from subscribers' computers and it has hit thousands of her fans and spread to up to 15,000 other websites, Mirror.co.uk reports.