HomeSecurityNational Student Clearinghouse: Data breach affects 890 schools

National Student Clearinghouse: Data breach affects 890 schools

The National Student Clearinghouse, a nonprofit educational organization in the United States, has disclosed a data breach affecting 890 schools across the country that use the organization's services

See also: Crown Point schools victims of ransomware attack

National Student Clearinghouse

In a letter submitted to the California Attorney General's Office, the National Student Clearinghouse reported that there was a breach on its MOVEit (MFT) server on May 30 and that files containing a wide range of personal information were stolen.

On May 31, 2023, the Clearinghouse was notified by our third-party software provider, Progress Software, of a cybersecurity issue involving the provider’s MOVEit Transfer solution,” the Clearinghouse said.

After becoming aware of the issue, we immediately launched an investigation with the support of leading cybersecurity experts. We have also coordinated with law enforcement.

The personally identifiable information (PII) contained in the stolen documents includes names, dates of birth, contact information, social security numbers, student ID numbers, and certain school-related records, such as enrollment records, degree records, and course-level data

According to the data breach notification letters, the information exposed in this attack varies for each affected individual. You can find the full list of educational organizations affected by this massive data breach here.

See also: Ransomware attack hits Lebanese schools

schools

The National Student Clearinghouse provides educational reporting, data sharing, verification and research services to more than 22,000 high schools and about 3,600 colleges and universities. The organization reports that about 97% of students enrolled are at public and private institutions.

The Clop ransomware gang is responsible for the large-scale data theft attacks that began on May 27. It exploited a well-known security flaw in the MOVEit Transfer file transfer platform.

Since June 15, cybercriminals have been blackmailing organizations that have fallen victim to attacks by revealing their names on a website that leaks dark web data. The fallout from these attacks is expected to impact hundreds of organizations worldwide, with many having already notified their customers of their impact over the past four months.

Despite the large number of potential victims, Coveware estimates suggest that only a few are likely to give in to Clop's ransom demands. However, it is expected that the criminal gang will collect around $75-100 million in payments due to the high demand for ransom.

See also: Rochester: Schools confirm ransomware attack

The reports also reveal that multiple federal agencies and two entities of the United States Department of Energy (DOE) have fallen victim to these data theft and extortion attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS