How did the data breach occur?
Criminal hackers who had a sophisticated understanding of computing systems exploited a vulnerability that allowed them access to sensitive data housed at the Ohio State Research Foundation, a unit within the Office of Research. This provided a route for the hackers to breach a database file containing sensitive information. The attack on the server was identified by OSURF staff while performing their daily review of activity logs. The staff responded immediately by moving the sensitive data to a site not accessible via any other server. University computer security personnel were immediately notified, as were appropriate off-campus law enforcement authorities.