Skip to content

University of California, Berkeley, takes several systems offline after suspicious activity

Containment began Aug. 26, the university said, while investigators assess possible data exposure and earlier service outages remain unexplained.

Stone facade and columned entrance of McLaughlin Hall at UC Berkeley, with “Engineering” carved above the doorway.
McLaughlin Hall at the University of California, Berkeley’s College of Engineering. (Pillsmarch/Wikimedia Commons)
Published:
Editor’s note: This story was updated Sept. 4 to include UC Berkeley’s response on when containment began, threat-actor attribution and the investigation into possible data exposure.

The University of California, Berkeley, took several systems in its Department of Electrical Engineering and Computer Sciences, known as EECS, offline after security software detected suspicious activity.

The university said Wednesday that campus IT restricted network access to affected EECS systems as it investigated the activity’s scope and potential impact. It did not identify the activity or say when it was detected.

Campus spokesperson Janet Gilmore told DysruptionHub Friday that comprehensive EECS containment efforts began Aug. 26. Instructional services were restored quickly to limit the effect on EECS courses, while affected faculty and staff received alternative access and workarounds. Central campus IT services were not affected, the university said.

A department IT status page shows that some EECS service problems began at least two weeks before the university’s announcement. A Unix login server went offline Aug. 18 and was slated to be replaced with a new virtual machine.

Screenshot of UC Berkeley’s Sept. 2 EECS security notice explaining that suspicious activity prompted network restrictions and systems to be taken offline.
UC Berkeley said in a Sept. 2 notice that it restricted network access and took several EECS systems offline after detecting suspicious activity. (Screenshot/UC Berkeley)

The department reported Aug. 25 that all Instructional and Research Information Systems services were down, including home- and project-directory storage, its website and a Unix login server. It said wired-network address assignment was restored Aug. 28, but the broader outage remained listed as active Friday. UC Berkeley has not said whether those disruptions were connected to the suspicious activity.

Gilmore said the suspicious activity has not been attributed to any known threat actor. The Daily Californian reported Friday that EECS lecturer Michael Ball said certain services were offline during the semester’s first several days but that the disruption did not greatly affect his courses.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Fall instruction began Aug. 26, one day after the broad service-outage notice. The department reported 1,720 undergraduate and 741 graduate EECS students in fall 2023, its latest figures published online.

UC Berkeley’s containment steps resemble those taken last month by the University of Texas at San Antonio, which shut down some systems after an attempted intrusion disrupted account access, registration, payments and phone service before fall classes.

Gilmore said the university is investigating whether data may have been exposed. UC Berkeley did not say whether unauthorized access occurred, whether all affected systems had been restored or whether the Aug. 18, Aug. 25 and Aug. 28 disruptions were related to the security response.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
Joseph Topping

Joseph Topping

Joseph Topping is the founder and editor of DysruptionHub, reporting on cyber incidents and technology failures that disrupt public services, organizations and daily life.

All articles

More in Education

See all

More from Joseph Topping

See all