Baptist University Reviews IT Security After Ransomware Group Claims Breach
SCMP · 1 SOURCESabout 2 hours ago2 MIN

Summary
Baptist University has launched a comprehensive review of its information technology security systems following claims by ransomware group The Gentlemen that it successfully breached the Hong Kong institution's network and accessed sensitive data. The cybercrime group, which first emerged in mid-2023, reportedly obtained credentials belonging to staff, students, and third-party employees totaling approximately 1,900 accounts. The university confirmed it is investigating the allegations and coordinating with local authorities and regulatory bodies.
Key Points
- Ransomware group The Gentlemen, which operates on a revenue-sharing model by renting extortion software to other hackers, claimed responsibility for the breach
- Approximately 1,900 credentials may have been compromised, including 130 staff accounts, 1,770 other user accounts, and 260 third-party employee credentials
- Baptist University issued a statement confirming awareness of the alleged breach and said it is closely reviewing system security and personal data protection
- The Office of the Privacy Commissioner for Personal Data stated it had not received official notification but had proactively contacted the university
- Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, recommended immediate notification to the privacy watchdog, forensic investigations, campuswide password resets, and multi-factor authentication
Why It Matters
This incident highlights the escalating threat of ransomware attacks targeting Hong Kong's educational institutions, where sensitive research data and personal information of thousands of students and staff are stored. The scale of potential credential compromise underscores the need for robust cybersecurity measures across academic institutions, as successful breaches can enable further social-engineering attacks and data exfiltration affecting the broader university community .
This incident highlights the escalating threat of ransomware attacks targeting Hong Kong's educational institutions, where sensitive research data and personal information of thousands of students and staff are stored. The scale of potential credential compromise underscores the need for robust cybersecurity measures across academic institutions, as successful breaches can enable further social-engineering attacks and data exfiltration affecting the broader university community .