500 Melbourne Uni staff in hacker’s global education protest leak

  • Liam Tung (CSO Online (Australia))
  • — 03 October, 2012 12:07

Anonymous-affiliated hackers protesting against the high cost of education and large student loans have published \more than 120,000 records from dozens of top universities, including the University of Melbourne.

Links to the files, posted on PasteBin by Team GhostShell, lead to the leaked database tables of staff and students from universities across the US, Japan, UK, Germany, Russia, Switzerland, Norway, Italy and Australia.

“Our targets for this release have been the top 100 universities around the world. After carefully filtering the ones that we've already leaked before and the ones where Anonymous has in major operations, we have eventually got together a new fresh list,” Team GhostShell wrote, labelling the campaign “Project WestWind”.

The only Australian university included in the hackers’ list was the University of Melbourne. The file contains system profiles of more than 500 engineering staff, which are listed alongside phone, email, username and in some instances a brief bio of their achievements. In some cases, the details leaked contain no more than what is available on the university’s web-facing staff profiles.

Each target’s leaked file contains a link to the page, presumably where the hackers exploited a flaw to access the database.

The group claimed “a lot” of the servers they accessed were already injected with malware.

“No surprise there since some have credit card information stored,” it said.

Follow @CSO_Australia and sign up to the CSO Australia newsletter.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

ZENworks® Endpoint Security Management

Secure, identity-based protection for your endpoints

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.