“Guys, this is a scam right?”
My group chat of friends suddenly turned into amateur investigators as we tried our best to verify an email from someone who claimed they were a UC Berkeley School of Law alumna asking recipients to resolve “items that require your attention,” by logging in through an external link. Maybe the fact that we were all English and political science majors explains why it took us a bit longer than necessary to realize its malicious intentions.
Smaller-scale scams like this join a litany of outside cyber threats — it’s hard to forget the nationwide chaos the ShinyHunters’ Canvas breach caused during finals week last semester. It’s becoming increasingly apparent that the identity of “student” puts us at risk.
My friends were onto something: It doesn’t seem surprising to us that our bCourses logins are information worth going for. Students, upon matriculation, consent to immense amounts of personal information being logged onto what should be a secure database. Students don’t have a choice about handing in that information when entering UC Berkeley; it’s a sacrifice we didn’t necessarily know we were signing up for. Our digital doubles are uploaded onto a distant online world, leaving one feeling more and more defenseless.
The institution that should be protecting our information doesn’t seem to always have this interest at heart. Last September, UC Berkeley turned over the personal information of approximately 160 students, staff and faculty to the federal government. Escalating tension in higher education toward pro-Palestinian advocacy groups led to UC Berkeley being targeted — along with four other UC campuses — by the Department of Education and participating in their investigation of antisemitic inquiries. In moments of political pressure, students’ privacy seems to take a backseat to the demands of the national government. Being a student has always been political. What has changed is the ease of targeting and discovery enabled by technology that completes tasks by blindly probing for information, with little regard for privacy or legality.
Schools have set a precedent of being comfortable surrendering students’ private information while artificial intelligence technology is learning how to escape security perimeters and breach secure databases on its own. This worrying trend is further complicated by UC Berkeley’s decision to pour money and attention into the technology that’s breaking into secure systems of its own accord, chiefly AI.
Recently, the federal government returned to Berkeley through the Department of Energy’s Genesis Mission, which includes 23 UC and Lawrence Berkeley National Laboratory projects. The Genesis Mission, launched in 2025 by an executive order, is a national initiative led by the DOE along with 17 laboratories, which aims to connect the nation’s best “supercomputers, experimental facilities, AI systems, and unique datasets” to propel American innovation.
Berkeley is actively funding technologies that have proven their ability to go rampant and attack private databases in an unhuman, unpredictable way.
This summer saw advancements in agentic AI, which managed to make an already hostile virtual world even scarier. July brought AI models capable of escaping sandboxes, or set security parameters, when an OpenAI test model escaped and broke into a real company’s servers. ChatGPT agents, when tasked with investigating cybersecurity weaknesses to complete a “hacking exam,” found logins on the internet to gain access to the company, Hugging Face, which is described as an “app store for AI tools.” Later, it was revealed that these rogue agents also gained entry to several other “publicly-available services.” The landscape of coding and computer science is changing at a foundational level, at an unprecedented pace.
Just a couple short years ago, when this sort of technology only existed in the fictional constraints of sci-fi horror, researchers at UC Berkeley warned the world of the full-stop boundaries needed to “keep AI from killing us all.” When asked, UC Berkeley professor Stuart Russell listed “not breaking into other computer systems” as a “red line,” which is something “that AI systems are absolutely not supposed to do.”
The OpenAI escape exposes the vulnerability of teeteringly secure systems. As UC Berkeley defines itself as a top global leader in AI development, purportedly “shaping the future of this emerging field while exploring the larger implications of AI on society,” it must not forget its responsibility to consider the peril of the unknown, especially for its own students. Now that AI is capable of leaving test environments and entering supposedly secure databases, how do universities, as leaders in the field, reconcile their identity as both political envelope pushers and known targets?
In a hostile political atmosphere like this, we should ask ourselves, as students and student activists: How much information do we owe our universities?
UC Berkeley students are forced to reimagine the limitations of their activist potential. Students should feel safe to speak up to institutions and exercise the power of their influence. Our college culture is forced to reconcile with previously unthinkable technology. Now it is important to be aware of the undisclosed dangers inherent to being part of a university’s database. Although absolute abstinence from information disclosure is impossible, awareness is paramount.
While AI companies and researchers contest for another breakthrough, keep your information close and consider how little may be stopping a couple anonymous agents from digging up your data in a far-off lab.