UM victim of cybercriminals again, this time as an exercise

UM victim of cybercriminals again, this time as an exercise

"We all decide not to let ourselves be blackmailed"

01-04-2025 · News

Privacy-sensitive data ends up on the dark web, computers get infected with malware, and there are warnings of DDos attacks. And as if that isn’t enough, a group of student protesters have taken over a room in the administrative building. Last Thursday, Maastricht University took part in a nation-wide exercise on cybersecurity organised by ICT organisation SURF. “Because of all the changing signals, at a certain point you didn’t know what was fact and what was fiction.”

When it comes to cybersecurity, Maastricht University has learned its lesson. On 23 December 2019, cybercriminals managed to paralyse the institution with a ransomware attack, resulting in UM paying nearly 200 thousand euros in ransom. And while that money (including over 300 thousand in ‘profit’) has since been returned, the total damages were significantly higher – starting with just the increased digital security.
More recently, last January, UM was the victim of cyberattacks again, just like other institutions in the south of the country. The DDos attacks ultimately didn’t have a huge effect at Maastricht; it mainly led to slow or no internet for the staff and students.

Unity Revolt Movement

This is the fifth nation-wide exercise on cybersecurity that national ICT organisation SURF has organised. Thursday, 27 March, it was the turn of the universities. While a handful of people at UM was aware of SURF’s plan, the majority of the sixty people involved knew nothing. Almost nothing, said Vice-President Jan-Tjitte Meindersma when he spoke to Observant at the end of the day. At the start of the week, some fake news articles about a student protest had cropped up online (on a page specially created for the exercise), he said. The so-called Eenheid Opstand Beweging [Unity Revolt Movement], made up of students and employees from all over the Netherlands, are fighting for “a more honest and humane education system”, their manifesto read. “We demand that universities and colleges join us and stop passively spectating.”
Initially, it was just a digital protest calling on people to sign a petition, but on doomsday itself, a physical protest took place outside the administrative building on Mindersbroedersberg, which even resulted in the protesters occupying a room. (Just to be clear, this was all still part of the exercise.)

Dark web

That morning, a few hours earlier, Meindersma receives an anonymous email stating that a wide range of privacy-sensitive data had been leaked onto the dark web. Slowly, the news spreads that the computers of all the people who had signed the Eenheid Opstand Beweging petition had been infected with malware. Plus a warning that there will be DDos attacks. Meindersma: “Things are going wrong on all sides and you have no idea if one thing is linked to another.” The crisis protocol is implemented, a crisis management team gathers at UM, including a university spokesperson (important for both internal and external communication), the data protection officer, someone from the CISO (central information security office), and Meindersma himself. And as if things aren’t complicated enough, the latter also has another job: he is the national administrative leader for cybersecurity and has to get to work on behalf of all institutes. Because it’s not just UM facing cyber problems on 27 March, it’s every university.

Puzzle pieces

“The changing signals” complicate matters, said Meindersma, looking back – a thorough evaluation is set to follow. “There were many rumours. This one said the leaked data was real, that one said fake. What you want, as a crisis management team, is facts, something you can take action on and communicate about. You can’t do anything with rumours.”
In the afternoon, it becomes clear to Meindersma and his colleagues around the country that the cyberattacks and protests are down to one single group: the so-called Revolution Reckoners. They demand that the universities publish an open letter in the media promising to invest more in education and student support. If that money has to come out of the research budget, “so be it”, the protester’s manifesto states. Should the directors fail or refuse, then sensitive information will be released. Meindersma: “Then you see, partly because of the time pressure and partly because it’s ‘just’ an exercise, that we all decide not to let ourselves be blackmailed and refuse to give into the demands. In the back of your mind, you are, of course, thinking of a damage control plan and the question ‘what if the sensitive information is released’.”
While it was hard work, Meindersma considered the exercise “incredibly educational and valuable. It sometimes felt like an escape room. There is a time pressure and you have to find all the pieces of the puzzle.”

Author: Wendy Degens

Illustration: Simone Golob

Tags: cyberattack, surf, attack

Add Response

Click here for our privacy statement.

Since January 2022, Observant only publishes comments of people whose name is known to the editors.