The University of California, Berkeley, took several systems in its Department of Electrical Engineering and Computer Sciences, known as EECS, offline after security software detected suspicious activity.
The university said Wednesday that campus IT restricted network access to affected EECS systems as it investigated the activity’s scope and potential impact. It did not identify the activity or say when it was detected.
Campus spokesperson Janet Gilmore told DysruptionHub Friday that comprehensive EECS containment efforts began Aug. 26. Instructional services were restored quickly to limit the effect on EECS courses, while affected faculty and staff received alternative access and workarounds. Central campus IT services were not affected, the university said.
A department IT status page shows that some EECS service problems began at least two weeks before the university’s announcement. A Unix login server went offline Aug. 18 and was slated to be replaced with a new virtual machine.

The department reported Aug. 25 that all Instructional and Research Information Systems services were down, including home- and project-directory storage, its website and a Unix login server. It said wired-network address assignment was restored Aug. 28, but the broader outage remained listed as active Friday. UC Berkeley has not said whether those disruptions were connected to the suspicious activity.
Gilmore said the suspicious activity has not been attributed to any known threat actor. The Daily Californian reported Friday that EECS lecturer Michael Ball said certain services were offline during the semester’s first several days but that the disruption did not greatly affect his courses.
Fall instruction began Aug. 26, one day after the broad service-outage notice. The department reported 1,720 undergraduate and 741 graduate EECS students in fall 2023, its latest figures published online.
UC Berkeley’s containment steps resemble those taken last month by the University of Texas at San Antonio, which shut down some systems after an attempted intrusion disrupted account access, registration, payments and phone service before fall classes.
Gilmore said the university is investigating whether data may have been exposed. UC Berkeley did not say whether unauthorized access occurred, whether all affected systems had been restored or whether the Aug. 18, Aug. 25 and Aug. 28 disruptions were related to the security response.