Server hack at Georgetown Univ. probed

06.03.2006

"We are making every reasonable effort to notify affected individuals," he said. Georgetown has established a toll-free phone number, 1-866-740-2458, and a Web site http://identity.georgetown.edu where people can get more information.

According to a university source close to the incident who requested anonymity, the server in question was under the control of an individual who was not technically qualified to be a systems administrator.

"Because we're a university and fairly open, there are many computing fiefdoms all over the place," often run by individuals with grant money, the source said in an e-mail. Because the university information system office has not figured out a way to manage these independently run computing environments, there can be gaps in security, he said.

In an e-mail informing the university community about the incident, Georgetown's CIO, David Lambert, said the broad base of research and service programs conducted across campus "creates an additional responsibility for every research principal investigator, department chair and program director in the university to focus attention on information security.

"As part of our increased focus on the security of all systems in the Georgetown network, the security office will launch a program throughout the spring and summer focused on enhancing the security of confidential information contained on campus and departmental servers," Lambert said without elaborating.