DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Grand Valley State University hit by ransomware but remains publicly silent

Posted on June 22, 2022 by Dissent

According to its website, Grand Valley State University (GVSU) in Michigan currently has 19,239 undergraduate students and 3,027 graduate students. The university offers 141 undergraduate and graduate degrees and employs 1,760 faculty members and 2,050 support staff members. Almost all of their students get some kind of financial aid.  Those are some commendable statistics.

But will those statistics be remembered or will their students and employees be more likely to remember that in May, GVSU experienced a ransomware attack by Vice Society and some of their personal data wound up leaked on the internet?

Image: GVSU.edu

On June 14, the Vice Society ransomware group added GVSU to their leak site. Departing from what has been their usual habit for a while now, Vice Society did not immediately just dump the data from their victim. Instead, they simply listed GVSU and provided a prominent countdown clock showing how much time was left until Vice Society would leak GVSU’s data if their ransom demands were not met. The clock was set to leak the data on June 18.

On June 14, DataBreaches emailed GVSU to inquire about the incident. Other than an autoresponder that a ticket had been opened, there was never any response — despite the fact that reminders and additional requests were sent to the IT Department and to multiple named individuals on June 14, June 16, and then again on June 18 (after data had been leaked).

To be clear: the leak itself is not the worst leak DataBreaches has ever seen in terms of exposing student or employee data. A lot of the leaked files were somewhat innocuous and appeared to relate to assignments. DataBreaches did not spot any major databases like student financial aid records or employee payroll or HR databases. Nor did DataBreaches spot any any databases with Social Security numbers of students or employees (some files have SSN as part of their filenames, but no SSNs were in the data). The most concerning files, perhaps, were the passports and identity documents for several dozen people.

Getting no reply from GVSU, DataBreaches reached out this week to a former graduate student at GVSU via Facebook messenger. We had spotted a number of identity documents for this individual in the leak, and we asked him if GVSU had alerted him that his identity info is freely available online at this point. No reply has been received, but we hope he will follow up on our message so that he can protect himself.

Although GVSU has ignored repeated inquiries, Vice Society did reply to this site’s questions. Via email, they informed DataBreaches that they first gained access to GVSU’s system on May 24. Although they did not reveal how they gained access, they commented that gaining access was “easy enough.”

The spokesperson also estimated that more than 90% of GVSU’s system wound up encrypted — including GVSU’s backups. [Note that DataBreaches is reporting Vice Society’s statements, but their claims have neither been confirmed nor refuted by GVSU.]

When asked whether the university negotiated with them at all about their ransom demand, the spokesperson responded that they negotiated for about 9 days. “They offered 75k, then 150k, then they stopped talking.”  The spokesperson indicated that they had asked more than $150,000 but would not reveal the amount they had demanded.

DataBreaches has been reporting on education sector breaches for a number of years now, and took the opportunity to ask Vice whether in their experience, school districts or universities were getting any better at preventing attacks, or if the education sector is still a walk in the park for them.

“You know… some are still unprotected at all, some are protected well,” their spokesperson replied, adding, “We can still  attack most networks of education sector.”

Sadly, DataBreaches has no reason to doubt that claim.

If anyone has seen any statement from GVSU about this incident or has actually received any individual notification, please let us know by email to breaches[at]databreaches.net.


Chum1ng0 assisted in researching this incident.

Category: Breach IncidentsCommentaries and AnalysesEducation SectorMalwareU.S.

Post navigation

← Daycare Apps Are Dangerously Insecure
Vice Society claims responsibility for attack on one of Milan’s most important hospital systems →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Evoke Wellness to Pay $1.9 Million to Settle FTC Claims That They Misled Consumers Seeking Substance Use Disorder Treatment
  • Former Hilliard treatment center employee accused of selling patient data on dark web
  • Trump Rewrites Cybersecurity Policy in Executive Order
  • AMI Group – Travel & Tours notice of ransomware attack
  • Resource: Insider Threat reports
  • Za: Cyber extortionist sentenced to eight years in jail
  • ICE takes steps to deport the Australian hacker known as “DR32”
  • Hearing on the Federal Government and AI
  • Nigerian National Sentenced To More Than Five Years For Hacking, Fraud, And Identity Theft Scheme
  • Data breach of patient info ends in firing of Miami hospital employee

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy Victory! Judge Grants Preliminary Injunction in OPM/DOGE Lawsuit
  • The Decision That Murdered Privacy
  • Hearing on the Federal Government and AI
  • California county accused of using drones to spy on residents
  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.