A little of everything professional. This site contains the largest online collection of electronic signature laws and research, my views on Time Management & GTD life hacks for improving productivity, and my After Thoughts on bad decisions and business improvements. Personal thoughts and casual comments are pushed to my SEO project, The World's Greatest Guy.

University of Texas at Dallas Loses 6,000 IDs

Google AdSense ad placeholder here

The UT Dallas breach is not the first breach of data the University of Texas System has seen even this year. In October, the UT System appointed a chief information security officer to build and oversee a system-wide plan to protect UT's information after some recent exposures. What I find so frustrating is that unlike businesses whose public opinion rating can result in the loss of millions of dollars in profit, Universities seem to depend on the fact that the ID's being stolen are merely students who lack the maturity, financing and time to actually force these institutions of learning to act with even the slightest sense of liability. The University of Texas treats ID theft like a common burglary, where the store owner is the victim and everyone should be saddened that the University has been a target of hacking. As an Alumni, I feel for the students of a school that has repeatedly put our information at risk.

You do not have to be a 'rocket scientist' to know that using a person's social security number as a student ID is just plain dumb and illegal (SS# are only to be used for TAX purposes). Yet it appears that every school insists on using this most valuable number for their own internal tracking purposes. I have seen my student ID left lying around on carbon-copy paper, in teacher's role sheets and of course on just about every test you take. And for what? Sure it makes the news when 6,000 ID's are theft exposed to the world, but what about the constant disregard for personal information security? How many ID's have been compromised from the school's use of social security numbers as student IDs?

Dr. Daniel, UTD President, said the university believes the hacker attack came from the outside using the Internet as if this is supposed to make me feel better. It feels that the school is trying to play on the ignorance of society on the subject of ID theft. People commonly view ID theft as a burglary. The store own is victimized because the criminal break through a glass window and stole a few hundred dollars. Sure I feel sorry for the store owner, but institutions that hold data worth millions and millions of dollars should be treated differently. The average public often fails to see what is going on in the background and thinks of computer systems as safes in a bank - isolated from the outside world. However a look at recent headlines tells a different story when IDs are frequently lost on company laptops and common hard drives.

When I was a student at UTD, I had no say when it came to my private information. I was at the mercy of the school... If you want to attend and receive student loans they had to use your social security number. To illustrate this point - the first year or two at UTD I requested a random student ID. When you go to the Library, Union, Advising, Counseling, Student Services or any where else, they always said 'what's your Social Security #' and when I would say, 'you mean my student ID?' they would have this most confusing expression compounded by the fact my former student ID was this randomized number. In a day and age when people shred their mail and ink out the credit card number on purchase receipts, I find the University of Texas at Dallas stubborn disregard for personal information contemptible.

Major Security/Hacking Events of the UT System:

  1. December 14, 2006 - UT Dallas attacked again with 6,000 users affected.
  2. September 2006 - 2,500 student records for University of Texas at Arlington students were stolen at the end of September.
  3. April 2006 - The UT System's flagship school in Austin's McCombs School of Business breach exposed the records, including Social Security numbers and other sensitive information, of 197,000 people.
  4. 2003 - UT Austin has suffered a major IT security breach

According to Id Theft Center, at least 192 incidents have been disclosed in 2006 alone, potentially affecting more than 12,004,393 million individuals. Many of these attacks were directed at Universities and centers of learning. Here is a list of the Universities attacked in 2006.


Date Users Affected School
1/1/2006 159
University of Delaware
1/3/2006 700
University of Pittsburgh
1/3/2006 2,400
Illinois Education Assoc
1/13/2006 NA
Notre Dame
1/13/2006 19,000
Kent State
1/23/2006 1,600
University of Washinton Medical Cntr
1/27/2006 12,000
College of St. Scholastica
1/27/2006 2,500
University of Colorado
1/30/2006 4,000
University of Texas M.D. Anderson Cancer Center
1/31/2006 240
Purdue
Feb-06 9,800
UAB School of Medicine
2/17/2006 6,000
University of Northern Iowa
2/25/2006 20,000
Vermont State Colleges
Mar-06 5,000
University of Michigan Credit Union
3/2/2006 93,000
Metropolitan State College of Denver
3/2/2006 51
University of Delaware
3/3/2006 41,000
Georgetown University
3/24/2006 2,100
University of Southern Mississippi
3/24/2006 2,486
California State University
3/24/2006 342
University of Nebraska
3/26/2006 NA
Shorter College, Rome, GA.
Apr-06 20
Oklahoma State University
4/7/2006 1,850
University of Medicine and Dentistry of New Jersey
4/8/2006 1,000
University of Delaware
4/9/2006 1,400
University of South Carolina
4/20/2006 39,000
University of Alaska Fairbanks
4/21/2006 106,000
University of Texas at Austin
4/21/2006 NA
University of Virgina
4/23/2006 137,800
Ohio University
4/26/2006 1,351
Purdue University
4/27/2006 NA
State of Georgia
4/28/2006 25
Purdue University
May-06 6,500
University of Kentucky
May-06 17,000
Northwestern University
5/4/2006 60,000
Ohio University
5/8/2006 135,000
Sacred Heart University
5/8/2006 851
Miami University
5/23/2006 1,294
California State University
5/24/2006 4,719
University of Texas at El Paso
5/26/2006 1,300
University of Kentucky
6/1/2006 2,800
San Francisco State University
6/5/2006 240,000
Western Illinios University
6/6/2006 4,900
Barnard College of Academic Technologies
6/30/2006 280
University of Iowa
Jul-06 NA
Belhaven College
7/12/2006 1,500
Morine Park Technocal College
Aug-06 12,000
Louisiana State University
Aug-06 13,000
University of Minnesota
8/14/2006 710
University of Kentucky
8/14/2006 184
Adams State College, Coloado
8/16/2006 64,000
University of Texas - San Antonio
8/18/2006 6,000
University of South Carolina
8/28/2006 1,400
University of Colorado
Sep-06 2,093
Berry College
Sep-06 2,500
Purdue College of Science
Sep-06 1,000
Louisiana State University - Alexandria
9/29/2006 2,500
University of Texas - Arlington

9/29/2006

14,500
University of Iowa
12/14/06 6,000
University of Texas - Dallas

 

As an alumni, the UT Dallas Response was sent to me by email.

Dear UT Dallas Alumni,

I regret to inform you that approximately 6,000 students, faculty, staff, and alumni at the University of Texas at Dallas as well as other individuals potentially have had sensitive information exposed by a computer network intrusion.

The personally identifiable information that may have been exposed includes names, addresses, Social Security numbers, email addresses and telephone numbers.

There is no indication that the information has been disclosed, disseminated or used to anyone's detriment at this time. However, the University does not seek to minimize concerns raised by this intrusion, and in the best interests of those potentially affected seeks to notify anyone whose information may have been disclosed.

The individuals whose information is known to be involved at this time include:

* In the Erik Jonsson School of Engineering and Computer Science, students, faculty, and alumni as well as applicants for admission dating back as far back as 1993.

* All staff and faculty of the University who were employed from January 1999 through August 2005.

The potential disclosure of data was discovered Sunday, December 10, by The University of Texas at Dallas information resources staff. The University of Texas at Dallas is responding aggressively to defend the integrity of the system and to assess the level of the threat to information contained on the system. Most but not all of the networked computing resources on campus have been assessed. Investigation is ongoing and updated information will be issued via email and the University homepage.

Every effort will be made to contact those individuals whose information could have been exposed. If you are concerned that you might be affected by this intrusion, you are encouraged to go to https://www.utdallas.edu/datacompromise/form.html to submit contact information so that the University can respond, or call 972-883-4325 to leave contact information.

Further information about protecting yourself (whether your information has been disclosed or not) is available at http://www.utdallas.edu/datacompromise/. UTD Staff will continue to assess and respond to the situation.

A press release on this incident has been issued in an effort to contact as many affected individuals as possible. The press release is available at http://www.utdallas.edu/news/archive/2006/network-intrusion.html.

If you have additional questions or concerns, please feel free to contact Erin Dougherty in Alumni Relations at (972) 883-2328 or erin.dougherty@utdallas.edu. We care very much about protecting the privacy and confidentiality of our alumni records.

Again, the University is actively working to notify individuals who may have been affected, and we deeply regret that the data in our network were potentially exposed by a deliberate attack through the Internet.

Thank you.

David E. Daniel
President
The University of Texas at Dallas


Google AdSense ad placeholder here

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd><p><b><i><blockquote>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
Are you really a real person? Oh sure, like I can just trust you. Hey that's ASCII art! Cool.
  __  __                   _       _       _____ 
| \/ | __ _ _ _ | |__ | | | ____|
| |\/| | / _` | | | | | | '_ \ | | | _|
| | | | | (_| | | |_| | | | | | | |___ | |___
|_| |_| \__,_| \__, | |_| |_| |_____| |_____|
|___/
Enter the code depicted in ASCII art style.