Skip to main content
Back to overview
High

SANS Institute Suffers Data Breach Affecting 28,000 Member Records Due to Phishing Attack

The SANS Institute, a cybersecurity training organization, confirmed a data breach that exposed personally identifiable information (PII) of approximately 28,000 members.

Key points

  • The SANS Institute, a cybersecurity training organization, confirmed a data breach that exposed personally identifiable information (PII) of approximately 28,000 members. The incident was discovered on August 6, 2020, during a routine review of email
  • SANS Institute Suffers Data Breach Affecting 28,000 Member Records Due to Phishing Attack

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jan 1, 2020
Updated
Aug 5, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

SansData DisclosureSANS Institute Suffers Data BreachAffectingPhishing Attack The SANS InstitutePIISANSOfficeThe SANS InstitutePhishing Attack

Quick context

Questions about this signal

What happened in this signal?

The SANS Institute, a cybersecurity training organization, confirmed a data breach that exposed personally identifiable information (PII) of approximately 28,000 members. The incident was discovered on August 6, 2020, during a routine review of email configurations and rules. An investigation revealed that a SANS employee had fallen victim to a phishing attack, leading to the compromise of a single email account. The attackers used a malicious Office 365 add-in to establish an email forwarding rule, which subsequently forwarded 513 emails to an unauthorized external address. The forwarded emails contained subsets of PII, including email addresses, first and last names, work titles, company names, industries, addresses, and countries of residence. SANS stated that no passwords or financial information were compromised in the breach. The organization promptly removed the malicious forwarding rule and add-in, and began notifying affected individuals.

When was this signal reported?

Shadow Tier lists Jan 1, 2020 as the signal date.

Which organization is connected to this signal?

Sans is the organization connected to this public signal.

Explore Sans
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence