The possibility can’t be ruled out, says Jacques Beursgens, director of the ICT Service Centre. “The world of cybersecurity is like an arms race”, he explains. “Hackers are constantly looking for new ways to bypass organisations’ security systems.” And even the best security is only as strong as its weakest link – the individual user of a laptop or PC. “If a user accidentally clicks on a dodgy link or downloads malicious software, you can only hope your security system will intervene in time.”
More than two million "alerts" each year
According to Beursgens, UM’s security system has been significantly improved since the cyberattack. “December 2019 was a reality check in that sense; a lot has changed since then.” The university has hired additional IT staff, its network is now monitored 24/7 by the company Fox-IT, more sophisticated detection software has been installed on laptops and PCs, and staff are now required to use two-factor authentication (a password and a numerical code) when logging in.
How often is this improved security system put to the test? According to Beursgens, more than two million “alerts” of potentially dangerous incidents are recorded each year. “Not all of these are cyberattacks. They include websites attempting to install software without permission, suspicious network activity and malware downloads. And, more recently, CEO fraud” – scam emails where fraudsters impersonate a higher-ranking person to trick UM employees into transferring money.
Further cyberattacks
Each year, UM’s cybersecurity team thoroughly investigates around seventy incidents, says Beursgens. On two or three occasions, active measures are required: “This could involve isolating a computer or disabling an account because the user has downloaded malicious software, for example.”
There have been further cyberattacks since the 2019 incident, Beursgens reveals, but he declines to specify how many. “All attempts have been repelled.”
The ransom
Part of the ransom UM paid in cryptocurrency was recovered in early 2020. Due to a rise in Bitcoin’s value, the recovered amount was reportedly worth half a million euros. Beursgens, however, dismisses any notion of “profit”. He points out that the costs of the cyberattack and its aftermath are “dozens of times higher each year”, noting that UM spends “over €1 million annually” on cybersecurity.
There has been no news regarding the emergency fund for students, which UM previously said would benefit from the extra money recovered.
Eindhoven University of Technology announced on Monday afternoon that teaching would remain suspended on Tuesday. It is not yet clear whether the cyberattack has caused damage comparable to the 2019 Maastricht incident or who is behind the attack on Eindhoven's university.