Active Network, a provider of software (accounting) for schools of all levels, has disclosed a serious data breach that occurred last week.
Active Network, which is based in the US and has many customers, said hackers gained access to Blue Bear, a platform that helps educational institutions manage their accounting and student tuition. The platform is also used by online stores that sell educational products.
The software provider is warning that parents who visited online stores powered by Blue Bear to pay tuition or purchase books and other school supplies between October 1, 2019, and November 13, 2019, may be at risk. Specifically, their personal data, as it may be in the possession of hackers.
The information that has probably been stolen is: names, payment card number, card expiration date, security , and username and password (used to access the online store).

The school continues the investigations into the breach incident, but has already sent a letter to the students' parents to inform them.
Based on the data targeted by the hackers, the provider believes it may be a web skimming attack, also known as Magecart. It appears that the hackers breached the Blue Bear platform and installed malicious code on the school's online stores (which rely on Blue Bear) to collect payment cardsin real time when purchasing products or paying for tuition.
Magecart attacks were very common in 2019. The FBI had warned the US private sector to implement effective security measures to protect online stores and prevent the financial data of usersand customers from being compromised.
