Urgent.News

What's breaking now, across thousands of outlets.

Tech

Baptist University reviews IT security after ransomware group claims breach

Baptist University has said it is reviewing the security of its information technology (IT) systems after a ransomware group claimed online to have illegally accessed the Hong Kong institution’s data. The allegations were made by “The Gentlemen”, an advanced cybercrime group that first appeared in the middle of last year. Cybersecurity monitoring platforms reported that about 1,900 credentials…

Baptist University reviews IT security after ransomware group claims breach

Baptist University is conducting a review of its IT security measures following a ransomware group's claim of unauthorized access to the institution's data. The Gentlemen, an advanced cybercrime group, first emerged last year and made the allegations public online. The cybersecurity monitoring platforms detected potential compromise of approximately 1,900 credentials associated with the university. These credentials included roughly 130 staff accounts, 1,770 other user accounts, and 260 third-party employee credentials.

The Gentlemen is known to operate on a revenue-sharing model, renting its extortion software to other hackers, and has rapidly expanded its operations across global networks. Baptist University acknowledged the claim in a statement released on Tuesday night, expressing the need to closely review the security of its systems and personal data. The institution assured that it would take appropriate action under established mechanisms and maintain communication with local regulators and law enforcement agencies.

The Office of the Privacy Commissioner for Personal Data in Hong Kong has not received any official breach notification from the university. Upon learning of the incident, the office proactively reached out to the institution to gather more information about the situation. Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, strongly recommended that the university immediately notify the privacy watchdog, initiate comprehensive forensic and system checks, verify whether the stolen credentials have been used to infiltrate core systems or lead to data leakage.

Fong further advised the university to enforce a campus-wide password reset, mandate multi-factor authentication, cooperate with regulators and police, and maintain transparent communication with staff and students regarding the investigation's progress. This is crucial to prevent further social-engineering attacks.

Written by urgent.news from South China Morning Post - Hong Kong's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at scmp.com →

More in Tech

More from Tuesday 11 August →