Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Tuesday, December 26, 2023

Virginia’s Fairfax Schools Urged to Clean Up Privacy Safeguards After Data Probe


Superintendent Michelle Reid said the district would follow the advice of a firm it hired to examine a massive disclosure of student information.

Virginia’s Fairfax County Public Schools, one of the nation’s largest districts, should make several changes to safeguard student privacy, according to legal experts who investigated the recent accidental release of sensitive, confidential records on more than 35,000 students. 

Several of the documents were internal memos about special education services and litigation against the district that included the names of two former students who had brought lawsuits related to alleged sexual assaults. Another spreadsheet identified at least 60 students struggling with mental health issues including suicidal thoughts, self harm and eating disorders.

In the future, investigators said that attorneys should review and label files before a parent inspects them and urged staff throughout the district to be trained on the “importance of redacting and safeguarding confidential information.” In a letter to families Thursday, Superintendent Michelle Reid said the district would comply with all of the recommendations...

Virginia’s Fairfax Schools Urged to Clean Up Privacy Safeguards After Data Probe – The 74 (the74million.org)

Tuesday, March 29, 2022

Personal data of 820,000 NYC students compromised in hack

The personal data of about 820,000 current and former New York City public school students was compromised in a January hack.

The breach of Illuminate Education, a taxpayer-funded software company the city’s Department of Education uses to track grades and attendance, resulted in a hacker gaining access to students’ names, birthdays, ethnicities and English-speaking, special-education and free-lunch statuses, sources said.

The students’ social security numbers and family financial information were not collected by the DOE and were not compromised, according to the sources...

https://nypost.com/2022/03/26/nyc-students-have-personal-data-hacked/

Monday, November 2, 2020

Montgomery County Inspector General Again Raises The Alarm On Data Security Breaches


Montgomery County’s Inspector General is raising concerns for the second time this year about personal information of children being at risk of a security breach.

Megan Limarzi released a report Tuesday concerning at least 529 child victims of sexual or physical abuse or neglect at the Tree House Child Advocacy Center in Rockville. Their names, biographical data, medical information, clinician, notes and details of their abuse were available to any county employee or contractor that had access to a shared platform as of late September.

The Inspector General didn’t say whether the data was actually accessed by unauthorized users, but that the question should be pursued.

Limarzi reported on another set of unsecured documents in May. That case involved Medicare benefits applications stored on a shared platform at the county’s Department of Health and Human Services, involving social security numbers, date of birth, Medicare numbers, bank checking account numbers, and applicants’ addresses.

Limarzi says county agencies aren’t taking seriously recommendations to either delete the sensitive information or restrict access to personal documents on the shared platforms...

https://dcist.com/story/20/10/27/montgomery-county-inspector-general-again-raises-the-alarm-on-data-security-breaches/

Wednesday, October 16, 2019

MCPS: Personal student information, test scores breached

SILVER SPRING, Md. (AP) — A school district in Maryland says a student improperly downloaded personal information and test scores of more than 1,000 students from a college preparation program.
A Montgomery County Public Schools statement says the data breach happened Oct. 3 and impacted 1,344 Naviance accounts tied to Wheaton High School in Silver Spring. Naviance is an online program that enables students to prepare for college and careers.
District spokesman Derek Turner told The Washington Post that the student wrote a program or algorithm that tried various combinations of usernames and passwords to gain access...

Monday, April 4, 2011

College Board Students Customers at Risk

Reuters is reporting that Epsilon's data breach includes College Board student customers.  Reporters are Jonathan Spicer and Maria Aspan.

Excerpt:
NEW YORK (Reuters) – The names and e-mails of customers of Citigroup Inc and other large U.S. companies, as well as College Board students, were exposed in a massive and growing data breach after a computer hacker penetrated online marketer Epsilon.

In what could be one of the biggest such breaches in U.S. history, a diverse swath of companies that did business with Epsilon stepped forward over the weekend to warn customers some of their electronic information could have been exposed.

Drugstore Walgreen, Video recorder TiVo Inc, credit card lender Capital One Financial Corp and teleshopping company HSN Inc all added their names to a list of targets that also includes some of the nation's largest banks.

The names and electronic contacts of some students affiliated with the U.S.-based College Board -- which represents some 5,900 colleges, universities and schools -- were also potentially compromised.

No personal financial information such as credit cards or social security numbers appeared to be exposed, according to the company statements and e-mails to customers.

Epsilon, an online marketing unit of Alliance Data Systems Corp, said on Friday that a person outside the company hacked into some of its clients' customer files. The vendor sends more than 40 billion e-mail ads and offers annually, usually to people who register for a company's website or who give their e-mail addresses while shopping.
For the full story go here.