Akira claimed 430 GB from Stanford's public safety department

Organization
Stanford University
Exploit
Ransomware
Industry
Higher Education

The Akira ransomware group added Stanford University to its dark web extortion site on October 27, 2023, claiming to hold 430 GB of internal data that it described as private information and confidential documents, and threatening to publish the files if the university did not pay.

Stanford said the incident involved the Stanford University Department of Public Safety, the campus police agency. The Stanford Daily noted that the department holds records on personnel, case reports, risk assessments and crimes involving students, faculty and other members of the university community.

The university confirmed it was investigating and said the affected system had since been secured. It stated that there was no indication the incident had reached any other part of the university and that the department's ability to respond to emergencies had not been affected. Stanford said its privacy and information security teams were working with external specialists on the review and would share more once it concluded.

Stanford did not confirm the 430 GB figure, describe the categories of data involved, or say whether a ransom had been demanded or paid. Akira, which emerged in early 2023, typically steals data before encrypting systems and publishes what it takes when victims refuse to pay. As of the end of October 2023 the university's investigation remained open.

Updates

  1. Stanford began notifying about 27,000 people on 11 March 2024 and said the intruder had been inside the Department of Public Safety network from 12 May to 27 September 2023, a far longer dwell time than was known at the time.

Sources