Data breach in the StudiCloud

23.03.2024

The AStA hereby informs you about a data breach in which data of students and external persons were probably made accessible to unauthorised persons:

What happened?

Several files containing information on internal financial data of the constituted student body of the University of Rostock from the years 2020 and 2021 were publicly available for four months in the StudiCloud, the cloud for student committees of the University of Rostock.
The reason for this event and its late discovery lies in the release structure of documents in StudiCloud. It is often not possible to see exactly who has access to which documents. Therefore, it was not realised that the above-mentioned documents were available to the university public.

When did it happen?

The incident was noticed in the night from 20 March to 21 March 2024. The documents had been available to the university since November 2023.

What data is affected?

In detail, the files contain the following personal data

  • Date of the transfer
  • Surname and first name
  • Payment subject
  • Transfer amount
  • IBAN and BIC in three cases
  • Signatures in three cases
  • Who has received the data?

The StudiCloud can be accessed by anyone who has a corresponding account at the University of Rostock. It is no longer possible to prove who actually accessed the documents, as the StudiCloud log data does not go back far enough.

What measures have already been taken to limit the damage?

The subfolder containing the documents has been deleted.

Awareness of the release of documents in the StudiCloud is being raised once again.
In particular, we are working on a better concept for processing data protection incidents to improve the implementation of measures and communication in the event of data protection incidents.

The StudiCloud settings for sharing documents will soon be revised to make the public settings clearer. The aim of this is to ensure that such errors can be avoided completely at best, but at least recognised at an early stage.

It is also planned to check all other documents in the StudiCloud for public access in a timely manner. However, it cannot be assumed that any other documents related to this incident are still publicly available at the university, as the folder in question has been completely deleted.

Posted by techast on in AKTUELL

Kalender

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
28
12:00 AM - AStA-Sitzung
29
30
31
1
2
3
4
12:00 AM - AStA-Sitzung
5
6
7
8
9
11
12:00 AM - AStA-Sitzung
12
13
14
15
16
17
18
12:00 AM - AStA-Sitzung
19
20
21
22
23
24
25
12:00 AM - AStA-Sitzung
26
27
28
29
30
28 Oct
28.10.2025    
0:00
Die Sitzung findet um 19:15 Uhr in Präsenz im Raum 131 in der Parkstraße 6 statt. The meeting will take place at 7:15 p.m. in [...]
04 Nov
04.11.2025    
0:00
Die Sitzung findet um 19:15 Uhr in Präsenz im Raum 131 in der Parkstraße 6 statt. The meeting will take place at 7:15 p.m. in [...]
10 Nov
10.11.2025-23.11.2025    
0:00
Mo., 10.11 tba. Di., 11.11. Netzwerk für Courage und Demokratie 15:15 - 16:45 Mitquizzen Mitdenken. Mitreden. – Dein Einstieg in politische Bildung" „Wie sprechen wir [...]
11 Nov
11.11.2025    
0:00
Die Sitzung findet um 19:15 Uhr in Präsenz im Raum 131 in der Parkstraße 6 statt. The meeting will take place at 7:15 p.m. in [...]
18 Nov
18.11.2025    
0:00
Die Sitzung findet um 19:15 Uhr in Präsenz im Raum 131 in der Parkstraße 6 statt. The meeting will take place at 7:15 p.m. in [...]
25 Nov
25.11.2025    
0:00
Die Sitzung findet um 19:15 Uhr in Präsenz im Raum 131 in der Parkstraße 6 statt. The meeting will take place at 7:15 p.m. in [...]
Events on 28.10.2025
28 Oct
28 Oct 25
Events on 04.11.2025
04 Nov
4 Nov 25
Events on 10.11.2025
Events on 11.11.2025
11 Nov
11 Nov 25
Events on 18.11.2025
18 Nov
18 Nov 25
Events on 25.11.2025
25 Nov
25 Nov 25