Thursday, November 26, 2015


UTSA Honors College informs students of computer security incident

Share this Story

(Sept. 22, 2011) -- The University of Texas at San Antonio is informing 688 students and prospective students who either enrolled in or applied to courses in the Honors College that an unauthorized user may have gained access to information about them. Those affected have been notified by personal letter.

During the data exposure, the records of a few UTSA students were accessed by unauthorized users in the Honors College section of the online system. When accessed, these records were pulled into the Honors College section. These students may receive the personal letter if it was possible their records were accessed, even if they were never enrolled in the Honors College.

The data exposure was discovered Aug. 2 and information exposed included name, date of birth, address, phone number, email address, GPA and other personal information. No Social Security numbers were part of the information exposed. Within an hour of discovering the unauthorized access, UTSA officials addressed the issue and initiated an investigation.

Examination of the data exposure indicated its characteristics were not consistent with an attack designed to gather data from the system, but rather an inadvertent misconfiguration of assigned access to the information.

"While we believe the situation has been completely contained, we want to notify each individual directly to make him or her aware of the incident and provide a contact at the university who can provide additional information if needed," said Richard Diem, dean of the UTSA Honors College. "The likelihood that the information was misused is very low, but our primary concerns are informing affected individuals and working to ensure that this never occurs again."

For more information, contact the UTSA Honors College at 210-458-4106.


Data Exposure FAQ

  • How did the data exposure occur?
    On Aug. 2, an employee discovered that the ASAP online information system used by the UTSA Honors College and other UTSA offices was accessible by users who didn't have a business need to access the application. The problem was resolved within an hour of discovery. The exposure was caused by a configuration error implemented June 20, allowing access to ASAP by all UTSA employees with ASAP access, rather than only authorized Honors College users. A thorough analysis and investigation of the incident determined that 233 records were accessed by unauthorized employees and 455 additional records may have been accessed.
  • How many students' records were exposed?
    The records of 4,700 individuals who were either qualified for the Honors College or were Honors College alumni were exposed (open to access), but only 688 records were accessed. It was determined that 233 records were accessed by unauthorized users. An additional 455 records may have been accessed by unauthorized users; the remaining 4,012 records were not accessed.
  • Who was notified of the data exposure?
    The 688 individuals whose records were accessed or which may have been accessed by unauthorized users were notified via postal mail and email, using contacting information on file.
  • I'm part of the Honors College, but I didn't get a communication indicating that my data was exposed. How can I find out if I was affected?
    All students whose records were accessed have been notified separately by both postal mail and e-mail. (See previous question.)
  • What could someone potentially do with my exposed information?
    Since the data was exposed to UTSA employees and was not the result of an attack, there is no indication and it is unlikely that exposed data was misused. It is possible someone could use such information to try to obtain more information about you, such as in a "phishing" email claiming to come from UTSA. Date of birth is sometimes used as a question to help validate identity. Social Security numbers, driver's license information and financial account information were not exposed, so the exposed information is highly unlikely to be used for financial identity fraud. Consequently, a security freeze and credit monitoring are not recommended as the result of the data exposure. However, free credit reports can be obtained annually from the three credit bureaus, and periodically reviewing your credit reports is a good way to reduce the risk of financial identity fraud.
  • What steps should I take because of the data exposure?
    Log in to ASAP and visit the Honors College form. Check to ensure that all of your information is correct. If the information that was exposed (such as date of birth) is used by you as part of a password or as an answer to a forgotten password question, consider updating that information. If you receive an email that claims it is from UTSA, inspect it to be sure that it is not a phishing email. UTSA will not contact you to ask for personal information such as this. For more information on protection from phishing, visit the UTSA Information Technology website.
  • Does UTSA have policies and standards in place to try to prevent data exposure?
    Yes, read the UTSA information resource use and security policy and the UTSA information security standards.
  • What steps are being taken as a result of the data exposure?
    The testing process has been revised to ensure that additional testing is performed in order to detect configuration errors before changes are implemented.

UTSA will share more information as it becomes available.



Dec. 1, 9 a.m.

CITE Venture Competition & Exposition

The annual Center for Innovation, Technology and Entrepreneurship (CITE) 100K Venture Competition and Exposition will be held on the Main Campus on Dec. 1. Twenty-eight teams from across the university will exhibit their project; six teams will compete for a prize pool of more than $100,000 in funding to launch their new venture / company. More than 650 students have participated in launching new technology ventures.
Biotechnology, Sciences and Engineering (BSE 2.102), Main Campus

Dec. 3, 5:30 p.m.

UTSA Downtown String Project Winter Concert

This concert features 50 community children performing music in the UTSA Downtown String Project Winter Concert. The children, led by UTSA music students studying to be music teachers, will join together in playing the Theme from Batman at their concert. The Batman of San Antonio, a local celebrity figure, will make an appearance at the concert. This event is free.
Buena Vista Theatre, Downtown Campus

Other Calendars
» UTSA Events | » Academic | » Institute of Texan Cultures

Submit an Event

Meet a Roadrunner

Jennifer Vassell writes children's books about health

Graduate student uses storytelling to highlight important issues facing children

Did You Know?

UTSA writes the book on all-digital libraries

As touch screens and e-books demand more and more attention from both casual readers and scholars, many people say the handwriting is on the wall for the printed page.

At UTSA, the handwriting is on the wall for a library that doesn't have any printed books.

Since March 2010, the bookless library in the Applied Engineering and Technology Building has given UTSA students an innovative way to read, research and work with each other to solve problems.

With ultra-modern furniture and a décor featuring desktop computers, scanners and LCD screens, the AET Library is designed to engage students in an online format. But it also offers group study niches and study rooms with whiteboards and glass walls on which students can write. The space encourages teamwork, communications and problem solving for the next generation of scientists and professional engineers.

Did you know? The UTSA AET Library is the nation's first completely bookless library on a college or university campus. It served as a model for Bexar County's first-in-the-nation public bookless library system and one of its branches, the Dr. Ricardo Romo BiblioTech.

Read More »

UTSA's Mission

The University of Texas at San Antonio is dedicated to the advancement of knowledge through research and discovery, teaching and learning, community engagement and public service. As an institution of access and excellence, UTSA embraces multicultural traditions and serves as a center for intellectual and creative resources as well as a catalyst for socioeconomic development and the commercialization of intellectual property - for Texas, the nation and the world.

UTSA's Vision

To be a premier public research university, providing access to educational excellence and preparing citizen leaders for the global environment.

UTSA's Core Values

We encourage an environment of dialogue and discovery, where integrity, excellence, inclusiveness, respect, collaboration and innovation are fostered.

Connect with UTSA News


Related Links

Back to Top

2015 © The University of Texas at San Antonio  | One UTSA Circle San Antonio, TX 78249 | Information 210-458-4011

Produced by University Communications and Marketing