UC Berkeley restricted access to the online systems in the department of electrical engineering and computer sciences after Berkeley IT identified suspicious activity across the department’s networks.
According to a statement by campus spokesperson Janet Gilmore, the activity has not been linked to any “known threat actors.” Campus is currently investigating if any data may have been exposed during the incident, as well as the incident’s “scope and potential impact.”
Gilmore said the activity was discovered using the “university’s security software,” endpoint detection and response.
This cybersecurity software monitors organizations’ endpoints, such as laptops, desktops, servers and mobile devices, which often serve as entry points for attackers. It works to secure those endpoints, increase their visibility and identify threats.
Restricting EECS networks was a part of a “comprehensive security protocol,” Gilmore said in the statement.
Central campus IT networks were not affected by the incident, according to Gilmore.
Gilmore said disruptions to faculty and staff IT are a result of “campus actions to protect EECS systems.” She added that IT has provided “alternative access pathways” for faculty and staff to access needed systems and functions.
After the activity on EECS systems, IT staff “quickly restored instructional services” for EECS courses, according to Gilmore.
EECS continuing lecturer Michael Ball said in an email certain services were offline for the first several days of the semester, but it did not greatly affect his courses, which he said “don’t currently rely on EECS infrastructure.”
This follows the May cyberattack by cybercrime group ShinyHunters, which took the online education platform Canvas offline. The group claimed to have stolen “more than 600,000” UC Berkeley student and staff records.