The Campus Data Breach That Woke Me Up to Cybersecurity

I was sitting in the university library, halfway through a mediocre essay on marketing strategy, when my phone buzzed with an email from the IT department. The subject line was blunt: “Security Incident – All Students Must Reset Passwords Immediately.” I skimmed it, annoyed at the inconvenience, and assumed someone had just clicked a bad link. Later that evening, the full story emerged. Hackers had breached the student records system and accessed thousands of files containing names, addresses, dates of birth, and even scanned copies of passports submitted for enrolment. My data was in there. For the first time in my life, cybersecurity wasn’t an abstract concept discussed in tech forums. It was personal, and I felt completely exposed.

Over the following weeks, I watched the aftermath unfold. The university held a town hall where a security consultant — a woman in her thirties with a calm, direct manner — explained how the attack had happened. She described a technique called “credential stuffing,” where attackers use username and password combinations leaked from other sites to break into accounts, knowing that people reuse passwords everywhere. I felt my stomach drop. I was one of those people. That moment of uncomfortable recognition sparked a curiosity that eventually reshaped my academic path. I wanted to understand not just how these attacks happened, but why we — students, institutions, ordinary people — kept making the same mistakes.

When it came time to choose a dissertation topic, I knew I wanted to explore cybersecurity, but I was immediately overwhelmed by the sheer breadth of the field. Network security, ethical hacking, cryptography, privacy law, human factors — each branch felt like a discipline in its own right. I needed a starting point that felt both manageable and meaningful. A friend suggested I look at collections of cybersecurity research topics for students to get a sense of the landscape. I spent an evening scrolling through them, discovering topics that ranged from the effectiveness of multi‑factor authentication in reducing account compromises to the role of public awareness campaigns in preventing ransomware attacks. Some were deeply technical, others were policy‑focused, and a few sat at the intersection of psychology and technology. That exploration helped me narrow my focus to something I’d experienced firsthand: the role of password hygiene education in reducing credential‑based attacks among university students.

With my direction clearer, I designed a mixed‑methods study. I surveyed students across three different faculties about their password habits and conducted follow‑up interviews to understand the psychological barriers to better security practices. My supervisor helped me ground the work in protection motivation theory and behavioural change models. Slowly, the project that had started with a panicked password reset became a genuine investigation into why humans are often the weakest link in any security system — and how we might change that.

If you’re a student interested in cybersecurity but unsure where to begin, think about a moment when technology made you feel vulnerable or exposed. Maybe your social media account was hacked, a family member fell for a scam, or your favourite app leaked your data. Those moments aren’t just annoyances; they’re research questions waiting to be asked. Then explore what other students have already investigated, and use their work as a springboard for your own curiosity. Cybersecurity needs people who can ask human questions, not just technical ones. You might just be one of them.

Scroll to Top