Attackers reportedly used compromised access connected to academic software provider Rashim Software to reach customer environments at Israeli universities and colleges. Op Innovate, which assisted one victim institution, said student data there was highly likely exposed—but it found no definitive proof that personal student data was stolen. The reporting does not establish a complete list or count of affected institutions.
How did hackers get into Israeli universities?
According to Dark Reading’s March 13, 2024 report, the group calling itself Lord Nemesis, also known as Nemesis Kitten, claimed it used credentials taken from Rashim Software to access systems belonging to the vendor’s university and college clients in Israel. Rashim provided academic administration software, including a student-focused CRM product.
Op Innovate said the hack-and-leak operation began around November 2023. On March 4, about four months after the initial breach, the group used Rashim’s internal Office 365 infrastructure to send a message to clients, colleagues, and partners claiming full access to the company’s infrastructure.
What Op Innovate said about the access path
Op Innovate reported that Rashim maintained an administrator account on at least some customer systems. According to the firm, attackers hijacked that account and used a VPN associated with a customer’s Michlol CRM environment to access organizations. The account of the incident also says Rashim relied on email-based authentication and that attackers compromised the vendor’s Office 365 infrastructure, undermining that authentication route. This is the access path reported for this case, not evidence that every software provider’s customer access is compromised.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
The precise method attackers used to enter Rashim’s own systems was not established in the report. Op Innovate CMO Roy Golombick said that detail remained confidential while the investigation was ongoing.
Was student data stolen?
Op Innovate said its log analysis found targeting of servers and databases, including a SQL server containing sensitive student data. The firm did not find definitive proof that personal student data was stolen. It assessed that student data at the institution it assisted was highly likely exposed. Exposure indicates a credible risk that data was accessed or available to attackers; it is not the same as confirmed theft.
That assessment concerns the institution Op Innovate assisted. The reporting does not establish the data outcome at every customer organization, and attacker claims or posted material do not independently prove the full extent of the compromise. Dark Reading reported that the group published videos purporting to show deletion of database branches and leaked personal videos and images of Rashim’s CEO; those reports do not by themselves establish what student records, if any, were exfiltrated.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Which universities and colleges were affected?
The available reporting does not give a verified, exhaustive victim list or a definitive count of affected institutions. Dark Reading said the campaign appeared to target Israeli organizations based on the group’s Telegram channel. The group’s claims should not be treated as independently verified proof that every named or implied institution was breached.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Dark Reading described Lord Nemesis as an Iranian hacktivist group and identified Nemesis Kitten as another name. Those are descriptions attributed to the reporting; the sources here do not provide a separate official government attribution.
What is a software supply-chain attack?
A supply-chain attack targets a supplier or service provider in order to exploit the trust and access that organizations give it. The Israel National Cyber Directorate’s supply-chain methodology describes attacks aimed directly at a supplier, such as a software provider or a trusted service provider working with an organization.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
In the Rashim case, the reported mechanism involved more than a flaw in software: a vendor-side compromise allegedly intersected with privileged customer access, VPN connectivity, and an authentication dependency. That combination can turn a compromised supplier environment into a route toward customer systems. It does not mean that using vendor software alone proves a customer network was breached.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can universities secure third-party vendor access?
Op Innovate CMO Roy Golombick advised organizations to apply multifactor authentication (MFA) to all users, including accounts used by third-party vendors, and to watch for suspicious activity such as logins outside normal hours. He also advised having a reputable incident-response firm on retainer so it can respond quickly when an incident occurs.
Assess supplier controls
The INCD methodology is intended to help organizations examine risks arising from supplier relationships and assess controls through a questionnaire available in the YUVAL system. It is guidance for risk assessment, not a certification that a supplier is safe. Organizations can use the process to scrutinize how suppliers access systems and what controls govern that access.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
Make vendor access visible and limited
- Require MFA for vendor accounts, as Op Innovate recommends.
- Monitor account activity for unusual timing, including out-of-hours access.
- Include supplier access and controls in formal supplier-risk reviews using the INCD methodology and questionnaire.
These steps address different parts of the problem: authentication, detection, and supplier oversight. The incident reporting does not specify a particular MFA product or security-key model, so organizations should verify that any chosen method works with their identity platform and vendor accounts.
Prepare for a rapid response
Op Innovate recommended arranging incident-response support in advance to make early response hours count. A response plan should give the organization a clear way to investigate suspicious vendor access and preserve relevant logs and evidence. The reporting does not rank incident-response providers or specify a particular service.
What remains unknown
- How attackers first entered Rashim’s systems.
- The complete number and identities of affected universities and colleges.
- Whether personal student data was stolen from the institution Op Innovate assisted or from other customers.
These uncertainties matter: the reported vendor access path and likely exposure at one institution are significant, but they do not establish a confirmed, campaign-wide theft of student records.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

