Hackers are blackmailing the University of Colorado (CU) after a cyberattack that “may have compromised” personal data from more than 310,000 records, including student data, medical information and social security numbers. The attackers have posted a small amount of data on the darknet and are threatening to release more if the university refuses to pay the ransom.
The university said it does not plan to pay the ransom, following guidance from the FBI, since paying would not ensure that the data would not be released now or in the future, or that additional ransom demands would not be made.
Spokesperson Ken McConnellogue said the university system, as well as individual departments and individuals, have been blackmailed by the attackers in recent weeks.
Read also: Data leaked from Stanford, Maryland and UC Berkeley Universities!

An email sent to a university student by the attackers on the morning of April 9th read the following: “The administration refuses to cooperate, so we are notifying you that some of your personal data has been published on the darknet and more will be published.”
The University of Colorado was notified of an attack on its file-sharing system — owned by Accellion — on Jan. 25 and immediately took the service offline. CU was one of at least 10 higher education institutions affected by the Accellion hack. About 50 institutions were affected by the attack, which the FBI is still investigating.
See also: Flagstar Bank: Customer data breached via Accellion hack
In February, when the University of Colorado first announced the attack, McConnellogue called it “the largest and most complex data incident” the system had ever seen. CU also suffered a cyberattack in 2005, in which 50,000 records.

Records stolen in the Jan. 25 attack include grades and transcript data, student ID numbers, race/ethnicity data, veteran status, visa status, disability status and limited donor information. Other records stolen include “medical care records, diagnostic and prescription information, and in limited cases, social security numbers and university financial account information,” the statement said.
Fewer than 20 Social Security numbers are in the 310,000 records exposed, according to McConnellogue. Of the 310,000 records, most belong to the Boulder campus and some to the Denver campus. The Colorado Springs and Anschutz campuses were not affected.
Suggestion: Hackers abuse Google Forms / Telegram to collect phished credentials

Those affected by this security incident will be notified next week, according to CU, and will be advised of the actions they need to take. The university system is providing credit monitoring, identity monitoring, fraud alerting and identity theft recovery to those affected for one year.
Additionally, CU no longer uses the Accellion software that the hackers were able to exploit. The software used by CU was one of “Legacy” , according to the company’s website, and was developed 20 years ago. Accellion has been working for three years to migrate its customers to a newer and more secure platform, Kiteworks, which was not affected by the attack, according to a statement from the company.
In February, Accellion announced the end of life date for its legacy file transfer software, also noting that it would not renew software licenses after April 30th.
Information source: securityinfowatch.com
