California News Beep | NewsBeep.com
  • News Beep
  • California
  • Los Angeles
  • San Diego
  • San Jose
  • San Francisco
  • Fresno
  • United States
California News Beep | NewsBeep.com
California News Beep | NewsBeep.com
  • News Beep
  • California
  • Los Angeles
  • San Diego
  • San Jose
  • San Francisco
  • Fresno
  • United States
UC Berkeley reports sweeping EECS cyber incident to law enforcement | Campus
OOakland

UC Berkeley reports sweeping EECS cyber incident to law enforcement | Campus

  • September 9, 2026

For two weeks, researchers and students in the electrical engineering and computer sciences department at UC Berkeley have been left in the dark concerning a massive and ongoing cybersecurity incident.

UC Berkeley is still investigating the incident and officials have told​​ The Daily Californian that law enforcement has been notified. While most EECS systems are now operational, some remain inactive as campus IT personnel work to fully restore the network.

The outage began Aug. 25, when all EECS Instructional & Research Information Systems, or IRIS, infrastructure was knocked offline.

“We are aware that all IRIS services are currently down. More information will be forthcoming as it becomes available,” wrote campus IT administrator Lars Rohrbach in an outage notice posted that day.

Campus spokesperson Janet Gilmore later told the Daily Cal in an email that campus began “containment efforts” the following day — claiming campus IT then took down “several systems” as part of a “comprehensive security protocol.”

Alongside teaching, professors and researchers in the EECS department conduct some of UC Berkeley’s most advanced research into AI and machine learning, with some projects funded by multimillion-dollar grants from the U.S. Department of Defense.

More than a week after the start of the incident, on Sept. 2, UC Berkeley’s Information Security Office posted the first update to the situation, stating campus had “recently identified suspicious activity” using the university’s cyberthreat identification and response software, Trellix EDR. 

Since the Daily Cal first reported the outage last Friday, campus administration has refused to provide details about the known scope or severity of the incident and continues to avoid referring to it as a hack or cyberattack. 

Gilmore did confirm that UC Berkeley reported the incident to “law enforcement”; however, she declined to name the specific agency or investigative body.

Most details about the incident remain unclear, as campus administration has restricted access to information concerning the outage; even many high-ranking EECS researchers and administrators have been left without answers.

One researcher, the director of a campus AI lab who was granted anonymity to speak freely on the topic, said he has not been briefed about the incident and was stonewalled when he tried to look into it.

“I asked, ‘Can you tell me?’, and (an IT staffer) said, ‘I’m sorry. I’m not at liberty to say,’” the director said. “That’s the first time that anyone has ever said those words to me (at UC Berkeley) … That suggests that (the staffer) would get in trouble if they said something.”

Gilmore has said UC Berkeley is investigating the “scope and potential impact” of the incident and claimed the activity has not been linked to any “known threat actors.”

Some of the systems affected, according to sources familiar with the outage, were large data centers aiding advanced AI research. This includes computers located in Warren Hall powering the Savio computing cluster. Savio has endured protracted compute and storage issues since April, and in July required an “urgent security update.”

IRIS oversees a wide range of campus IT infrastructures, including access to computing resources, research servers and student learning environments. Rohrbach’s original outage note referenced four services by name: Home Directory Storage, IRIS Website, Project Storage and Unix Login Server.

It is unclear if any student or staff’s personally identifiable information was affected; Gilmore did not say whether any data had been exfiltrated from EECS servers or what methods an attacker may have used.

“There’s something here that would reflect poorly on the university — that’s my guess,” the director said. “But of course, this is exactly what they don’t want, right? They don’t want speculation.”

The Daily Cal reached out to several EECS researchers and professors to investigate this incident, all of whom either declined to comment or reported a similar lack of knowledge.

The AI lab director said while access to research environments was affected for some time as their internal data centers were taken offline, most operations were either quickly restored or moved to external providers like Amazon Web Services.

The director’s AI lab does not conduct “export-restricted” research, work that is quarantined by the government from being shared on publicly accessible systems. Other labs on the EECS network, he said, likely do conduct this kind of research, particularly those working on projects sponsored by the U.S. government, especially the military.

“Some pages on our main website are still down (faculty homepages, etc.) but most services have been restored and IT has a process in place to assist any individuals who may continue to have issues,” Gilmore said in an email Tuesday. “Restoration is continuing, and most systems vital to research have been restored.”

  • Tags:
  • AI
  • amazon web services
  • berkeley
  • cyberattack
  • cybersecurity incident
  • daily cal
  • eecs
  • eecs instructional & research information systems
  • hack
  • home directory storage
  • information security office
  • iris
  • iris website
  • janet gilmore
  • lars rohrbach
  • Oakland
  • Oakland Headlines
  • Oakland News
  • project storage
  • savio
  • the daily californian
  • trellix
  • U.S. Department of Defense
  • UC Berkeley
  • unix login server
  • warren hall
California News Beep | NewsBeep.com
www.newsbeep.com