Dissent Doe :cupofcoffee: · @PogoWasRight
1313 followers · 142 posts · Server infosec.exchange

The gang appears to have hit the Bishop Luffa School in the U.K. Proof of claim screenshots have been posted, and the school supposedly has 7 days to cooperate before data are leaked.

@douglevin @brett

#medusa #ransomware #edusec #infosec #dataprotection #databreach #gdpr #cybersecurity

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1311 followers · 133 posts · Server infosec.exchange

Really have no idea how the heck I missed this one, but....

UChicago, NYU team find online education tools pose privacy risks.

News release (Feb. 21): cs.uchicago.edu/news/uchicago-

Paper: bpb-us-w2.wpmucdn.com/voices.u

@douglevin @funnymonkey who probably laughing hysterically at how late I am at spotting this one.

#edtech #edusec #infosec #privacy #dataprotection #online #virtual #learning

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1306 followers · 140 posts · Server infosec.exchange

Oh ugh ugh ugh.

In early February, Berkeley County Schools in West Virginia experienced a ransomware attack.  On March 3, the district issued a notice on its website that stated their investigation determined "some data stored in Berkeley County Schools’ network may have been accessed that included employee Social Security numbers and direct deposit
information."

That notice makes no mention of any student information being involved.

But Vice Society has added Berkeley County Schools to their leak site and has dumped a LOT of personal and sensitive info on students. Some of it goes back years, too.

Read my post at
databreaches.net/highly-sensit

That district has a LOT of accounting to do, and a lot of changes to their data retention and protection. And of course, FERPA doesn't actually require them to notify the students or families -- only to make notations in their records that the files were disclosed without authorization.

@douglevin @brett @allan @BleepingComputer @AlvieriD

#databreach #ransomware #edusec #dataprotection #incidentresponse #FERPA #infosec

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1305 followers · 138 posts · Server infosec.exchange

So Merced College has now reported the malware/encryption incident that occurred Oct 25 - Nov 3, 2022:

oag.ca.gov/system/files/Merced

They had disclosed an incident at the time, but the formal notification to the state seems .... late?

@brett @allan @funnymonkey

#databreach #dataprotection #malware #edusec #infosecurity #cybersecurity

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1303 followers · 142 posts · Server infosec.exchange

So I recently told you all that the Southeastern Louisiana University is the work of BianLian. They still haven't actually named them on their site, but there's a teaser/placeholder for them. There's also a placeholder for the other uni I was told BianLian had hit: Tennessee State University.

My source is someone involved in one of the two investigations and who has some knowledge of the other investigation.

@brett @BleepingComputer @campuscodi @allan @vxunderground

#databreach #edusec #ransomware #cybersecurity #incidentresponse #infosec

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1300 followers · 118 posts · Server infosec.exchange

Hacker stole bank account, Social Security numbers, and health plan info of Denver Public School employees:

9news.com/article/news/crime/d

The incident was between Dec. and January, but employees are first being sent letters now. No student info has been identified as involved so far.

#databreach #dataprotection #edusec #infosec #cybersecurity

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1288 followers · 107 posts · Server infosec.exchange

Scoop: a source with knowledge of the investigation tells DataBreaches that the Southeastern Louisiana University security incident was an attack by the BianLian group.

@brett @allan

#databreach #dataprotection #ransomware #infosec #edusec #cybersecurity

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1288 followers · 108 posts · Server infosec.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1288 followers · 109 posts · Server infosec.exchange

Add West Virginia University to any list of uni's reporting data leaks or breaches. This was a file with some patient-related info left exposed on a site used for their software development: health.wvu.edu/finance-and-bus

@brett @douglevin

#edusec #infosec #dataleak #databreach #hipaa #phi

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1288 followers · 107 posts · Server infosec.exchange

"The Little Rock School District is continuing to seek an attorney general’s opinion on the legality of holding private school board meetings when reacting to a cyber- or ransomware attack on a district’s electronic information systems: "

arkansasonline.com/news/2023/m

In this case, the board met privately and decided to pay ransom of $250k, which they then voted on publicly.

Now they ask, "Can a school board meet privately to discuss how best to respond to a threat actor when the alternative is to risk the disclosure by the threat actors of the personal information of school district patrons and employees?”

That seems to be predicated on the assumption that if they pay the attackers, the data will not be disclosed. I would be asking, "Can a school board meet privately and keep employees and families in the dark that their personal information may be in the hands of criminals who may already be misusing it?"

@douglevin @brett @funnymonkey

#databreach #ransomware #transparency #freedomofinformation #foi #edusec #infosec #cybersecurity

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1287 followers · 102 posts · Server infosec.exchange

Today's FERPA questions:

Part 1:

Assume parents of students sign a media release like the one attached to this post where the release mentions specific activities but also a more general release to promote the program.

Now assume that the district is the victim of a cyberattack and the attackers dump all the school photos with the students' names and student ID numbers.

Does the release allowing pictures of the student mean that there was no FERPA breach? I would say that the release is restricted to the activities mentioned in the release and that a data dump on the internet would still be a breach.

Agree or disagree?

Part 2. Now assume that the district's "Directory Information" exemptions include student photos unless the parent opts out. Assume the same attack and data dump.

Now is it a breach?

#FERPA #dataprotection #students #privacy #edusec #directoryinformation #databreach #cyberattack #infosec

Last updated 3 years ago

White Settlement Independent School District in Texas sent DataBreaches a copy of the notice they sent to staff and families concerning a breach that has since been claimed by LockBit:

databreaches.net/another-texas

@douglevin @brett @funnymonkey @allan

#ransomware #databreach #infosec #edusec #dataprotection #cybersecurity

Last updated 3 years ago

Doug Levin · @douglevin
427 followers · 66 posts · Server infosec.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1274 followers · 126 posts · Server infosec.exchange

Trove of L.A. Students’ Mental Health Records Posted to Dark Web After Cyber Hack: the74million.org/article/trove

@mkeierleber is singing my tune about the need for entities to disclose when sensitive data has been leaked. There is no requirement under to notify of that.

We need a federal law requiring notification in the event of a data dump or leak of personal and sensitive information, and not just for the education sector -- for ALL sectors.

Y'all can just wait until I rule the world, or we can keep encouraging legislators to do what should have been done years ago.

@brett @douglevin @allan @funnymonkey

#FERPA #databreach #dataprotection #edusec #notification #incidentresponse #ransomware #cyberattack #dataleak #transparency #infosec

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1256 followers · 159 posts · Server infosec.exchange

Another day, another school district hit. This time, it's the Wawasee Community School Corporation in Indiana. BlackCat has leaked almost 10 GB of files.

There doesn't seem to be any notice on Wawasee's website.

@brett @douglevin @funnymonkey

#edusec #ransomware #databreach #infosec #cybersecurity

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1254 followers · 143 posts · Server infosec.exchange

California Northstate University student and employee data stolen:

AvosLocker added the listing yesterday and dumped a file with 393 employees' 2022 W-2 files. They also claim to have student info.

databreaches.net/california-no

@brett @douglevin @jgreig

#edusec #infosec #cybersecurity #idtheft #taxrefundfraud #hack #databreach #dataprotection

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1254 followers · 139 posts · Server infosec.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1254 followers · 131 posts · Server infosec.exchange
Dissent Doe :cupofcoffee: · @PogoWasRight
1248 followers · 132 posts · Server infosec.exchange

New kids on the ransomware block or state actors pretending?

"DarkBit" locks the Technion in Israel with a hodgepodge of alleged motives:

databreaches.net/technion-univ

#databreach #ransomware #Technion #dataprotection #edusec #cybersecurity

Last updated 3 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1244 followers · 123 posts · Server infosec.exchange