On April 2, 2015, the California Office of the Attorney General disclosed a data breach affecting Auburn University, which had originally occurred on September 1, 2014. The incident exposed sensitive personal information of current, former, and prospective students, including full names, home addresses, dates of birth, Social Security numbers (SSNs), email addresses, and academic records. The compromised data poses significant risks, such as identity theft, financial fraud, and unauthorized access to educational histories. The breach did not involve ransomware or a direct cyber attack like phishing or malware deployment but rather stemmed from a vulnerability or unauthorized access to the university’s systems. The exposure of SSNs highly sensitive identifiers heightens the severity, as they are prime targets for long-term exploitation in fraudulent activities. The university was required to notify affected individuals and implement measures to mitigate potential harm, though the exact method of the breach (e.g., misconfigured database, insider threat, or external intrusion) was not specified in the report.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-49210
TPRM report: https://www.rankiteo.com/company/auoit
"id": "auo559091725",
"linkid": "auoit",
"type": "Breach",
"date": "9/2014",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Current, former, and '
'prospective students',
'industry': 'Higher Education',
'location': 'Auburn, Alabama, USA',
'name': 'Auburn University',
'type': 'Educational Institution'}],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Academic Records']},
'date_publicly_disclosed': '2015-04-02',
'description': 'The California Office of the Attorney General reported a data '
'breach involving Auburn University on April 2, 2015. The '
'breach occurred on September 1, 2014, and involved personal '
'information of current, former, and prospective students, '
'including names, addresses, dates of birth, Social Security '
'numbers, email addresses, and academic information.',
'impact': {'data_compromised': ['Names',
'Addresses',
'Dates of Birth',
'Social Security Numbers',
'Email Addresses',
'Academic Information'],
'identity_theft_risk': 'High (PII exposed)'},
'references': [{'source': 'California Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'California Office of '
'the Attorney General'},
'title': 'Auburn University Data Breach (2014-2015)',
'type': 'Data Breach'}