More than 160,000 affected by data breach at UC Berkeley
Hackers had access to a database for about six months at the University of California at Berkeley and stole health-related data on more than 160,000 students and other people who used the school's health services center. College officials said that the attack on the health center's database was discovered last month and that they are just now beginning to notify the affected people.
In a statement released Friday, Berkeley officials said that the attack did not affect the database that houses the University Health Services medical records, which includes information on patient diagnoses, treatment and therapy. Instead, the attackers went after a machine storing other personally identifiable information, including Social Security numbers and health insurance information.
The attack, which affects students, alumni and some parents of students, depending on how the health care coverage was set up, netted records going back to 1999, the school said.
Editor's Pick
"The server breach began on Oct. 9, 2008, and continued until April 9, 2009, when campus computer administrators performing routine maintenance identified messages left by the hackers. Administrators immediately activated an emergency security incident team to investigate the scope and impact of the breach; evidence uncovered to date suggests that the attack was launched by hackers based overseas. The attackers accessed a public Web site and subsequently bypassed additional secured databases stored on the same server," the Berkeley statement says.
Although the attackers did not get into the main health record database, according to Berkeley, they may have gotten access to some students' health histories.
"The hackers may have stolen information related to health insurance coverage and some medical information such as one's immunization history, UHS medical record number, dates of visits or names of providers seen or, for a student participating in UC Berkeley's Education Abroad Program, certain information from his or her self-reported health history," the statement said.
*Composite image via Shazari's Flickr photo stream.
Commenting on this Article is closed.
Today's Most Popular
- Adobe's Security Chief Talks About Driving Up The Cost of Exploits
- Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages
- New Tool Cracks Apple iWork Passwords
- Google: Bug Bounty Program Has Made Users Safer
- After Damaging Reports, Electronics Manufacturing Giant Foxconn Is Hacked
Most Commented Stories
-
Attackers Using Fake Google Analytics Code to Redirect Users to Black Hole Exploit Kit (7)
-
Flash With Sandbox in the Works for Firefox (4)
-
Apple Ships Huge Set of Patches for OS X (7)
-
Twenty Something Asks Facebook For His File And Gets It - All 1,200 Pages (55)
-
EU Asks Google to Delay Privacy Policy Changes (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



