2019 – 2020: When a cyber-attack brought the university to a standstill

Warning signs at the entrance of the University Library, in early January 2020

2019 – 2020: When a cyber-attack brought the university to a standstill

Series: The times they are (not) a-changin'

27-05-2026 · Background

How does the mind of a criminal hacker work? Apparently quite rationally. The group (either Russian or Ukrainian – it never became clear) behind the spectacular 2019 attack on Maastricht University’s computer systems clearly chose its moment carefully. In the early evening of 23 December, just before Christmas, hardly anyone would notice anything unusual happening on their computer. It allowed the virus to spread quietly – a silent night, though certainly not a holy one.

That same evening, at 7:35 pm, the university’s IT staff noticed that the network was slowing down. Soon after, the university went into crisis mode: it had become the target of a cyber-attack. Vital systems stopped working. To prevent the situation from getting worse, everything was immediately shut down. It was the start of a nightmare that lasted more than a week and had consequences that dragged on far longer. From timetables and emails to research data, nothing could be accessed – until the university paid up. This was ransomware: the hackers said they would provide a digital key to unlock everything once payment was made.

How could this have happened? Was UM’s cybersecurity really that weak? As the university later admitted, that was indeed the case. Too many systems that should have been separate were interconnected, and too many people had system-wide access. A well-planned attack stood a good chance of success. And it was well planned. Two months earlier, on 15 October, the hackers had sent phishing emails with links to the university – and someone had clicked on one. The next day, someone else did the same. It opened the door to malware that quietly mapped the entire network. As the final blow, UM got a Clop virus for Christmas.

Crisis centre

A university being brought to a standstill is no small matter. It made national news. But in those first few days, communication with both the university community and the media was poor. The Executive Board’s spokesperson was on holiday and saw no need to report to the hastily set-up crisis centre, led by Executive Board member Nick Bos, in the library on Grote Looiersstraat. As a result, his predecessor Fons Elbersen was brought in on 26 December. Another key figure was Bart van den Heuvel, the university’s Chief Information Security Officer. Ten months later, in an interview published online by Géant – a European network including SURF, the IT cooperative of Dutch education and research – Van den Heuvel revealed that he communicated with the hackers via his private email account. He insisted that from the outset, the communication strategy had focused on “transparency (…) everything communicated internally was also shared externally”.

At the time, Observant and other media outlets experienced things rather differently. If we managed to get hold of anyone at all, the responses were brief. For example, an external cybersecurity firm had been brought in, but the university refused to disclose which one. It later turned out to be Fox-IT. Spokesperson Elbersen was unflappable: “I keep reading that we are negotiating. I’ve never used that word.”

"Impossible dilemma"

But negotiations were clearly taking place. Nick Bos later called it an impossible dilemma – pay the ransom or leave the university paralysed for months? – but the Executive Board actually reached its decision within days. Just after Christmas, it was said that teaching would resume on 6 January. “That means they’ve paid up”, cybersecurity experts said. And they were right. On 30 December, internal sources who disagreed with the university’s lack of openness on the matter told Observant that the criminals had been paid around €200,000 to €300,000 (later confirmed to be 197,000 in bitcoin). At Elbersen’s urgent request, publication was delayed until 2 January to avoid interfering with the crisis team.

It was not until 5 February that UM finally gave a full account of what had happened – which was in itself unprecedented.

50 years of UM

Maastricht University was founded fifty years ago. In this anniversary series, we delve into our own archives to rediscover memorable, funny, relevant and curious news stories from the past.

You can find all previous articles in this series here

Author: Wammes Bos

Photo: Observant

Tags: 50 years UM,cyber attack,hackers,cybersecurity,crisis,communication,it,icts,ransom,instagram

Add Response

Click here for our privacy statement.

Since January 2022, Observant only publishes comments of people whose name is known to the editors.