HKBU Probes Alleged Ransomware Breach; No Ransom Demands Received
Bastillepost · 2 SOURCESabout 2 hours ago2 MIN

Summary
Hong Kong Baptist University is actively investigating an alleged cybersecurity breach involving ransomware group TheGentlemen, with at least 1,877 accounts potentially compromised. The university immediately engaged professional cybersecurity investigators and reported the incident to law enforcement. No ransom demands have been made, and the offending webpage has been taken offline.
Key Points
- Ransomware group TheGentlemen claimed responsibility for breaching HKBU systems, exposing data from 130 staff and 1,747 students or registered users
- The university received a notification about the breach and immediately activated its incident response protocols
- HKBU reported the incident to police and the Privacy Commissioner's Office for personal data protection
- Professional cybersecurity firms have been hired to conduct forensic analysis and assess the full scope of the breach
- The university has warned staff and students not to open suspicious email links or attachments
- The webpage claiming to publish the stolen data has been removed
- HKBU stated it has received no ransom demands related to this incident
Why It Matters
This breach highlights the growing vulnerability of Hong Kong's educational institutions to sophisticated cyberattacks, as universities store vast amounts of sensitive personal data. The university's prompt notification to authorities and transparency in communicating with affected parties sets a precedent for how such incidents should be handled, while the absence of ransom demands suggests the attackers may have been more focused on data exfiltration and reputation damage rather than financial gain .
This breach highlights the growing vulnerability of Hong Kong's educational institutions to sophisticated cyberattacks, as universities store vast amounts of sensitive personal data. The university's prompt notification to authorities and transparency in communicating with affected parties sets a precedent for how such incidents should be handled, while the absence of ransom demands suggests the attackers may have been more focused on data exfiltration and reputation damage rather than financial gain .