Pearson VUE has announced a data breach of its Credential Manager System, a certification tracking program used by companies such as Cisco, F5, IBM, Microsoft, and Oracle to issue diplomas and official certifications for various professionals.
According to the company's official statement, the data breach occurred through malware that was implanted on its servers by unauthorized third parties. This malware allowed third parties to gain access to sensitive data.
Pearson VUE stated that only the Credential Manager System application was affected by this specific incident.
“Because the Credential Manager System is specifically designed to meet specific customer requirements, we are working to understand how the issue may impact each of our customers,” the Pearson spokesperson said.
While it will take some time to assess the actual damage to each customer, the company was quick to state that no other sensitive information such as credit card numbers and social security numbers were leaked.
To prevent further malicious actions, the company took the Credential Manager System application offline and reported the incident to the competent authorities.
The affected businesses' certification systems will remain down until Pearson declares it is safe to restart the service.
