Cyber Criminals Have Universities in Their Sights as New Term Begins

22 Sep 2015

Cyber Criminals Have Universities in Their Sights ...


With the new study year getting underway, universities are under threat from cyber-attacks being made against their computer systems.

This time of year sees thousands of students either start university or return for new terms. As a result, the amount of information being inputted onto a typical university computer system is huge, making them a prime target for hackers. 

Phishing Scams aimed at Students

The latest scam comes in the form of phishing emails. Scammers are pretending to be representatives of the Student Loans Company and demand that students send them their personal details. It then warns that failure to respond will see students 'lose or delay' their September student finance payments. Fear of having a delayed loan payment is in some cases enough to cause students to follow the scammer’s demands.

The Student Loans Company is warning students not to disclose any details or respond to the email, which purports to be from Student Finance England. They should also avoid clicking the link contained within the email, as they risk installing malware on to their computers.

Not a New Threat

In the United States, from the period of 2006 to 2013, 550 universities reported a data breach. 2015 also saw a number of universities, including Harvard being hacked. 2015 also saw the University of Virginia and Pennsylvania State University experience security breaches, which were suspected to be the work of Chinese based hackers. Student credit card details and social security numbers were stolen at other US universities.

Insider Threats

As well as being the target of external threats, universities are also vulnerable to insiders. In the UK last year there were several reported incidents of students hacking university computer networks in order to alter their grades or to disrupt activity.

In May 2015, hackers attacked the University of London Computer Centre. The resulting breach left millions of staff and students unable to gain access to online resources. Several universities were affected by the attack.

Universities are breached in much the same way as businesses and home computers. The most common method used is ‘spear phishing’. Another major issue is that is often a lack of control on who is accessing the systems and what they are able to connect to, attach or download.

Emails with malicious links or attachments are opened which activates the malware and allows it to establish a beachhead inside the network and try to gain access. Another common method of gaining access to a system sees the hacker entering malicious code into websites that the students and staff regularly log into.

Another issue for universities to consider is that students have a range of different upbringings and students from overseas may not be aware of the cyber security risks.

As a result of the threat, universities are increasing their spending on cyber security.

Cyber awareness training for staff and students alike could go a long way to tackle the dangers. Courses like PGI’s  Cyber security Awareness course teaches the basics of cyber security and educates students of the main risks and how to avert them.   

Hopefully with the dangers posed by hackers becoming increasingly highlighted in the media, universities and other educational bodies are beginning to take the matter of cyber security seriously.

For more information on our services give us a call on 0207 887 2699 

For the latest PGI updates like our pages on LinkedIn – PGI,  PGI Cyber  Facebook– PGI,  PGI Cyber  and  Twitter

Share this article


Your free global geopolitical
risk dashboard

PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.

The Risk Portal gives users up-to-date information and analysis on global affairs.

The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.

Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.

Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.

Visit the Risk Portal

Subscribe to our Cyber Bytes Newsletter

Keep yourself in the loop with PGI by signing up to our Monthly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.

Get in touch today

For more information on how we can help you or your business, please contact us via:

Related News

CISMP, CISSP and CISM - what's in an acronym?

20 Mar 2017

There is a wide range of different security courses available, and a mind-boggling array of certific...

Read news article

International Womens Day - Pioneering Women in Tec...

08 Mar 2017

Pioneering Women in Technology – Katherine JohnsonThe Oscar season has been and gone. The...

Read news article

Law Firms and why they need cyber security

06 Mar 2017

Suffering a data breach can be devastating for any company but for law firms the impacts can be part...

Read news article
Back to the News Hub

Follow us

+44 (0)207 887 2699
©2017 PGI - Protection Group International Ltd. All rights reserved.
PGI - Protection Group International Ltd is registered in England & Wales, reg. no. 07967865
Registered address: Cascades 1, 1190 Park Avenue, Aztec W, Almondsbury, Bristol BS32 4FP