Kansas State University cyberattack knocks out VPN, email and campus services
- Organization
- Kansas State University
- Exploit
- Hacking
- Industry
- Higher Education
Kansas State University identified a disruption to some of its network systems at about 9:25 a.m. on Tuesday, January 16, 2024, the first day of spring semester classes. The university confirmed later that afternoon that the disruption was the result of a cyberattack.
Services taken out of action included the university VPN, K-State Today email, video hosted on Canvas and Mediasite, printing, some shared drives and the university's listserv mailing lists. K-State said its IT staff moved immediately to investigate and isolate the areas of concern, and that affected systems had been taken offline and would remain offline while the investigation continued.
The university engaged a third-party IT forensic expert to assist. It told students and employees to contact the IT help desk if they noticed anything unusual while using university technology, and directed department heads to work with their deans or vice presidents on the operational impact. Academic deans were given guidance on alternative video resources for classes.
A university spokesperson said the priority was to address the issue promptly while maintaining business and academic continuity. K-State enrolls roughly 20,000 students and employs about 1,300 faculty. As of the initial reports the university had not said whether any data had been accessed or taken, and had not named a threat actor. Kansas Governor Laura Kelly commented publicly on the state's cybersecurity investments in the days that followed.