Three massive cyberattacks dominated headlines this week. Each hit a different pillar of American society.
An Ivy League university lost the data of 870,000 people, Russian hackers (allegedly) infiltrated federal courts, and a principal city went offline for two weeks.
Here's what happened this week in cybersecurity and why it matters to you.
Columbia University suffered a massive cyberattack that exposed the personal information of nearly 870,000 people, including students, employees, and applicants. While unauthorized access began in mid-May, it went undetected for over a month until a technical outage in late June prompted an investigation. The probe revealed that hackers had exfiltrated a vast amount of sensitive data, with multiple outlets reporting that it included 460 gigabytes of information, which comprised Social Security numbers, health records, financial aid details, and academic records.
Key Insights:
What makes this breach particularly alarming is the scope of personal data compromised. Beyond basic contact information, the hackers accessed insurance details, demographic data, and health information that students had shared with the university during their enrollment years. Columbia is now offering two years of free credit monitoring to affected individuals. Still, for hundreds of thousands of people, their most sensitive details may already be in the hands of criminals.
Why This Matters For You:
If you've ever attended college, the university still has troves of data about you. Universities store decades of student data but often lack the robust security infrastructure of financial institutions or healthcare systems. As colleges digitize more records and expand online services, they become increasingly attractive targets for hackers seeking vast troves of personal information in one place.
Read More on Bloomberg.
Minnesota's capital city has been in digital darkness for over two weeks after the Interlock ransomware gang claimed responsibility for a cyberattack that disrupted St. Paul's government operations. The attack forced the city to shut down its network, leaving residents unable to pay bills online, access city services, or even schedule a simple parking permit.
Key Insights:
St. Paul will reset passwords for 3,500 employees as systems slowly return online. All employees also get a free year of credit and identity theft monitoring. The city refused to pay the ransom, and hackers retaliated by posting 43 gigabytes of files online, primarily from a shared drive used by the Parks and Recreation department. Meanwhile, scammers seized the chaos, sending fake invoices to residents desperate to pay their city bills.
Why This Matters For You:
This attack highlights how completely we all depend on digital infrastructure for basic civic life. Government ransomware attacks are transforming your local city services into potential cyber battlegrounds. And when your local government gets hacked, even mundane tasks like renewing a dog license can become impossible.
Read More on Bleeping Computer.
Hackers with suspected ties to the Russian government have breached the federal court system that handles sensitive legal documents across the United States, including sealed cases and national security files. The hackers exploited their access to monitor criminal cases in New York and other jurisdictions, providing Moscow with unprecedented insight into America's judicial system. The multi-year attack exploited outdated vulnerabilities in the court system's electronic filing system, which includes the public-facing PACER system.
Key Insights:
The breach exposed highly sensitive information that could reveal confidential sources and details about people charged with national security crimes. Think of it like someone rifling through your lawyer's filing cabinet, but this cabinet holds cases involving spies, terrorists, and classified operations. The court system has long been a target for foreign intelligence agencies because it contains a treasure trove of information about ongoing investigations and government secrets.
Why This Matters For You:
This hack echoes the devastating 2021 SolarWinds attack, highlighting how America's critical infrastructure remains vulnerable to sophisticated state actors. President Trump says he "could" bring up the breach during his imminent meeting with Putin today, but the real question is whether our courts can secure themselves before the next attack. Every sealed indictment and witness protection case may now be an open book to Moscow.
Read More on Reuters.
Before Anonymous wore Guy Fawkes masks, there was Cult of the Dead Cow, a ragtag collective of hackers, pranksters, and digital philosophers who emerged from Lubbock, Texas, in the 1980s. In 1998, they dropped a Windows backdoor called Back Orifice, sparking chaos, laughter, and furious headlines. It was about proving a point: Microsoft's security was a joke, and users were the punchline.
But what made cDc legendary wasn't just their code. It was their attitude. They fused punk rock swagger with political dissent, wrote manifestos, coined the term "hacktivism," and later pushed for ethical standards. Some members became cybersecurity pros. One ran for president. Others disappeared into the ether. But their justice-minded spirit still pulses in every modern breach that's meant to expose hypocrisy rather than harvest credit card numbers.
Want to understand cybersecurity culture? Start here. Cult of the Dead Cow was the conscience of the digital underground, before most people had even accessed the internet.
These are my go-to privacy + security tools. Some links are affiliate links. (They support this newsletter at no extra cost to you!)
Proton Mail - One of the more private and secure email services. Basic accounts are free.
Proton VPN – Keep your internet, browsing history, and connection secure with servers in over 120 countries.
Proton Pass - Protect passwords with an elite encrypted password manager. Supports 2FA codes, device sync, multiple vaults, notes, and more.
Proton Drive - Store your data safely. Get 5GB for free and enjoy peace of mind, knowing your files are safe.
Please read my two newsletters:
# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.
# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security so you can spot scams and stay safe without needing to become an expert.
Follow for extra insights:
Bluesky | X (Twitter) | LinkedIn | YouTube
PS: Do you have questions? Reply to this email!
Thanks for reading. More cutting-edge cybersecurity insights coming soon.
You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.