OU is isolating its network systems due to suspicious activity after the Fog ransomware group claimed to have breached the university’s systems over winter break. 

The ransomware group is claiming to have exfiltrated 91 megabytes of information consisting of employee contacts, financial data and contact phones and emails of state senators. 

“The University recently identified unusual activity on our IT network,” a spokesperson for OU wrote in an email to OU Daily Jan. 27. “Upon discovery, we isolated certain systems and are investigating the matter. As part of this ongoing process, measures are being implemented across our network.”

Fog operates a leak website where they threaten to post their findings if a ransom is not paid. OU has not commented on whether it will pay the ransom for the information exfiltrated.

The group was initially observed by the Kroll Cyber Threat Intelligence Team in May 2024. The ransomware group claiming to be behind the attack has a record of targeting higher education institutions in the U.S. by taking advantage of compromised VPN credentials.  

Christopher Freeze, an assistant professor of cybersecurity at OU-Tulsa, said compromised credentials are often caused by clicking a link from an outside source or by using the same password for different websites.

“In educational organizations, there's an open atmosphere of collaboration and cooperation and scientific discovery and intellectual curiosity,” Freeze said. “Sometimes clicking on links that's sent to somebody in an educational system that might seem to be of collaborative nature and it ends up downloading some malware that somehow might get through the organization's firewall.”

According to Kroll, Fog is known to do double extortion, a tactic where the group both encrypts and exfiltrates data, which increases the likelihood the ransom will be paid. 

Freeze said there are several types of double extortion, some of which do not indicate that information has been encrypted by an outside source.

“It’s either ‘we’ve taken your data and you’re not going to get access to the file’ or you think you don’t need to pay the ransom because (you) can go in and access the file but now they’re encrypted, so you still (have) to pay the website,” Freeze said.

According to The Record, large universities are often targeted during the holiday season when IT teams are lacking staff members. 

In the past two years, the University of Michigan and Stanford University have both suffered ransomware attacks. Both attacks forced the universities to take parts of their networks offline.

This story was edited by Anusha Fathepure and Ana Barboza. Gretchen Schultz and Avery Avery copy edited this story.

OU Daily standards

See an error? Earning trust is our duty. We correct errors atop stories. Identify an error, request a takedown or get in touch.

Independent and free since 1916: OU is committed to our editorial independence. You can help ensure our reporting remains strong and accessible to all invested in OU and Norman.

Want to comment? We value dialogue on issues we cover. On our social media accounts, we moderate disparagements, arguments and attacks, including those directed at our staff — and ban those repeatedly failing civility. The editor considers guest column submissions.