A serious cybersecurity incident has come to light after hackers gained unauthorized access to an online coding repository belonging to the University of Sydney. The breach resulted in the theft of files containing the personal data of thousands of employees, collaborators and students, causing intense concern among both the academic community and cybersecurity experts.

How was the attack detected and which systems were affected?
According to an official statement from the institution, the breach was limited to a single system and was detected last week, following suspicious activity in one of the university's online code libraries. The university acted immediately, cutting off the attackers' access and taking measures to secure the digital environment.
See also: Richmond Behavioral Health Authority: Data breach affects 113,000 people
At the same time, the relevant authorities, including the New South Wales Privacy Commissioner, the Australian Cybersecurity Centre and education regulators, were informed so that a coordinated investigation into the incident could be initiated.
What kind of data was found in the repository
Although code repositories are primarily used for software storage and development, the University of Sydney admitted that older data was also present in the system. This contained personal information of members of the university community, which significantly increased the severity of the leak.
The stolen data concerns more than 27,000 people. Specifically, approximately 10,000 current employees and associates (from September 2018 onwards), 12,500 former staff members and associates from the same period, as well as approximately 5,000 students and alumni, with records dating from 2010 to 2019, were affected. The data includes names, dates of birth, phone numbers, home addresses and professional information.
See also: Venezuela: Cyberattack targets oil company PDVSA

Is there a risk of leakage on the internet?
The university confirmed that the data was indeed hacked and downloaded by the perpetrators. However, there is no evidence so far that it has been published online or used for malicious purposes . However, experts point out that such information often appears months later on forums or dark web marketplaces.
University of Sydney: Support measures and recommendations for users
The University of Sydney, one of Australia's largest and most prestigious public universities with around 70,000 students and 10,000 staff, has begun sending out personalised notifications to those affected, with the process expected to be completed within the next month.
At the same time, a special support service for cybersecurity incidents has been created, offering guidance and advice. Those concerned are urged to be particularly vigilant about suspicious emails or phone calls, to immediately change their passwords and to activate multi-factor authentication where available.
See also: Pornhub: Hackers stole activity data of Premium users

A recurring problem for the organization
It is worth noting that this is not the first incident of its kind. In September 2023, the university suffered a data breach through a third-party service provider, resulting in the leakage of prospective student. The new incident highlights, once again, the growing cybersecurity challenges facing large educational organizations worldwide.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
