
Bluefield University, a private university in Bluefield, Virginia, suffered a cyber attack that involved threat actors hacking into its internal systems and hijacking emergency broadcasting systems.Bluefield University announced via a statement posted on its website that on April 30, it identified a security incident affecting its internal systems and immediately launched an investigation to understand the nature and scope of the cyber attack.The university’s investigation revealed that threat actors targeted its “mass alert system, RAMAlert”, which is used to send both SMS and email alerts to its students. The University also decided to postpone scheduled exams that were supposed to begin in May.“Faculty and students can safely use and access MyBU, Canvas, and library resources through the university’s website. Faculty need to continue not using Jenzabar and their bluefield.edu email address,” Bluefield said.The University is working with external cyber security experts to investigate the cyber attack and restore its internal network. It is, however, yet to share details about how the threat actors infiltrated its network. The University also said that it has no evidence of any stolen information being used for financial fraud or identity theft, but the possibility of the same cannot be ruled out."If you are contacted by anyone claiming to be involved in the incident, please don’t click on any links provided by the individual or respond,” Bluefield University added.A group of threat actors going by the name Avos (aka AvosLocker) claimed responsibility for the cyber attack and used the RamAlert system of the University to send emails and SMS to its students, threatening to leak the allegedly stolen information if the University decides not to pay the ransom.“Hello students of Bluefield University! We’re Avoslocker Ransomwar. We hacked the university network to exfiltrate 1.2 TB files. We have admissions data from thousands of students. Your personal information is at risk to be leaked on the darkweb blog.“DO NOT ALLOW the University to lie about severity of the attack! As proof we leak sample Monday May 1st 2023 18:00:00 GMT (2:00:00 PM),” the alert read.The group of threat actors eventually leaked a sample of stolen data that included a W-2 Tax Form for the University’s President and a document related to their insurance policy.Commenting on the news, Rebecca Moody, Head of Data Research at Comparitech, said, “We are seeing an increasing number of organisations avoiding recognition of a ransomware attack or "playing down" the effects of the attack at first. However, ransomware gangs are becoming ever more ruthless in their negotiations and release of data, forcing organisations to change tack.“To suggest there is no evidence of stolen data/identity theft when an attack is first discovered is a little naive. Where possible, ransomware gangs are going to steal data that they can use to intimidate the entity into paying if the entity refuses to pay/is able to decrypt its systems without paying the ransom.“So far this year, we have noted 25 confirmed ransomware attacks on US education institutions. In the first four months of 2021, we only noted 15, suggesting a vast increase in attacks across the education sector. The average ransom on education institutions in 2023 is $1.25m,” Moody added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543