Hackers email stolen student data to parents of Nevada school district

Wed, 29 Nov 2023 06:49:34 +1100

Andrew Pam <xanni [at] glasswings.com.au>

Andrew Pam
<https://www.bleepingcomputer.com/news/security/hackers-email-stolen-student-data-to-parents-of-nevada-school-district/>

'The Clark County School District (CCSD) in Nevada is dealing with a
potentially massive data breach, as hackers email parents their children's'
data that was allegedly stolen during a recent cyberattack.

CCSD is the fifth largest school district in the US, with over 300,000 students
and 15,000 teachers.

On October 16, CCSD confirmed it suffered a cyberattack earlier this month,
stating threat actors gained access to the district's email servers.

"On approximately October 5, 2023, Clark County School District ("CCSD") became
aware of a cybersecurity incident impacting its email environment," reads a
statement from the Clark County School District.

"Upon discovering the incident, CCSD immediately engaged a team of forensic
experts to investigate the incident and ensure that CCSD operates within a safe
and remediated email environment. CCSD is also cooperating with law
enforcement's investigation."

"Thus far, the investigation revealed that the unauthorized party accessed
limited personal information related to a subset of students, parents, and
employees. CCSD is working diligently to identify all individuals whose
information was impacted by this incident."

In response to the attack, CCSD disabled access to its Google Workspace from
external accounts and has forced reset all student's passwords.

Since then, things have taken a turn for the worse, with parents reporting they
are receiving emails from the threat actors warning that their child's data was
leaked.'

[...]

'"For 6 years they forced students to use their birthday as their password,
resetting the passwords back to their birth date each year, they even prevented
the students from securing their accounts."'

This is a truly terrible security policy. Never do that.

Via Diane A.

Cheers,
       *** Xanni ***
--
mailto:xanni@xanadu.net               Andrew Pam
http://xanadu.com.au/                 Chief Scientist, Xanadu
https://glasswings.com.au/            Partner, Glass Wings
https://sericyb.com.au/               Manager, Serious Cybernetics

Comment via email

Home E-Mail Sponsors Index Search About Us