On the morning of 9 February, WPI identified unauthorized activity on our website server. Upon discovery, we immediately secured the website and server, took the necessary and advisable steps to examine the environment for comprimises, and deployed the website to a new, secure server.  Our review indicates that the former server was used to host unauthorized files. At this time, we do not believe any private customer data was compromised. The affected server does not store payment information, and all user passwords are stored in cryptographically secure, hashed form. Out of an abundance of caution, we recommend that users reset their passwords for the WPI website. Our web team is continuing to review logs across connected systems and...