University of Utah Paid Over $450K to Ransomware Attackers
The State of Security
The University of Utah paid a fee of more than $450,000 to attackers after they infected a portion of its servers with ransomware.
On July 19, 2020, the Information Security Office (ISO) notified the university’s College of Social and Behavioral Science (CSBS) that ransomware had infected some of its servers.
ISO responded by isolating the CSBS servers from the rest of the university’s network, notifying law enforcement and enlisting the help of an outside consultant to investigate what had happened.
This investigation revealed that the ransomware had infected approximately 0.02% of data contained on the CSBS servers. That information contained both employee and student details.