Data belonging to three US universities has been stolen and leaked online in the latest breaches related to a vulnerability in software . The universities targeted were Stanford University, the University of Maryland at Baltimore, and the University of California at Berkeley (UC Berkeley). All three universities have one thing in common: Their stolen data was leaked by the Clop ransomware.

More specifically, regarding Stanford, the data was stolen from the university’s School of Medicine and includes names, home addresses, email addresses, Social Security numbers and financial information, according to a statement issued by the Stanford Daily on April 1. The university has taken appropriate action, including hiring a cybercrime investigation firm, notifying affected individuals and contacting law enforcement. There was no report of ransomware, although it was noted that access was gained through a vulnerability in the Accellion FTA (File Transfer Appliance).
Read also: Data allegedly stolen from Shell and numerous universities leaked

As for the University of Maryland, Baltimore, it reported that it was hit by a ransomware attack in December 2020 , and the stolen data has now been leaked. This includes various personal information, including federal tax documents, passports, addresses, and Social Security numbers.
According to Yahoo News and other sources, the university disabled Accellion's system in February. Unlike Stanford, the University of Maryland appears to have responded more promptly to the incident, already providing security assistance, including credit monitoring and identity restoration services, to individuals whose data was breached.
See also: Facebook: Millions of users' data leaked - How to see if your data was exposed

Similarly, regarding the University of California at Berkeley (UC Berkeley), there is no report of ransomware, however its case differs slightly from those of the other two US universities. Holders of university email accounts received emails stating that their personal data had been stolen and would be leaked.
The list of known victims of the vulnerable version of the Accellion FTA server includes, among others, Bombardier, Jones Day, Qualys, Royal Dutch Shell and the Washington State Auditor's Office (SAO).

Proposal: Bombardier: The Clop ransomware group leaked company data!
Jerome Becquart, CEO of identity solutions provider Axiad IDS Inc., pointed out that organizations need to keep their various systems secure and up to date. Specifically, he said the following: “As our digital ecosystem becomes increasingly complex, the challenge of maintaining and patching systems is increasing exponentially. That’s why we’re increasingly seeing the adoption of a platform approach, it’s the only way forward.”
Information source: siliconangle.com
