The Register Home Page

back to article Scotland's university procurement center confirms cybercrooks broke in

Advanced Procurement for Universities and Colleges (APUC) says attackers gained unauthorized access to historical data in a cyberattack earlier this month. The Scottish education procurement body said it immediately contained the mid-July intrusion and was investigating claims that some of the data had been stolen. "We recently …

  1. Sam Lowry

    We asked APUC … whether it could identify any inaccuracies

    "We are aware that the group responsible for the unauthorized access has claimed to have taken some historic data from our systems."

    As a Scottish graduate I'm _authorised_ to remind you…

    Historic = something important or significant in history.

    Historical = things from the past, without implying importance.

    I guess our procurement centres of expertise ain't what they used to be ;-)

    1. Excellentsword (Written by Reg staff)

      Re: We asked APUC … whether it could identify any inaccuracies

      I almost put [sic] but didn't want to be that guy.

      1. Yet Another Anonymous coward Silver badge

        Re: historic data .... going back 20 years

        I know life expectancy in Scotland is not exactly world-leading

        But 20 years ago isn't exactly historical

      2. MachDiamond Silver badge

        Re: We asked APUC … whether it could identify any inaccuracies

        "I almost put [sic] but didn't want to be that guy."

        Ahh, go ahead, fill yer boots.

        1. Michael

          Re: We asked APUC … whether it could identify any inaccuracies

          With sic? That sounds unpleasant.

  2. MachDiamond Silver badge

    Dare I ask

    Why should this data be accessible via the internet?

    1. Richard 12 Silver badge

      Re: Dare I ask

      It may not have been.

      It sounds like the miscreant acquired administrator rights. Many system protections permit admins to export large blocks of data to disk (eg make a backup), even if plebs cannot.

      Once exported it'd be trivial to upload it all somewhere.

      1. MachDiamond Silver badge

        Re: Dare I ask

        "It sounds like the miscreant acquired administrator rights. Many system protections permit admins to export large blocks of data to disk (eg make a backup), even if plebs cannot."

        If one can root a system from the internet to get unlimited or admin rights and move data, I consider that data as internet accessible. My CAD computer is not internet accessible as it's devoid of a network connection. While my accounting computer is network connected, connections are restricted and its only on when I'm actively using it.

        Physical access leaves an attack surface, but it takes an insider.

  3. Anonymous Coward
    Anonymous Coward

    Security fried?

    Like all things Scottish?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon