{"id":129539,"date":"2023-10-02T17:30:04","date_gmt":"2023-10-02T21:30:04","guid":{"rendered":"https:\/\/rbach.net\/?p=129539"},"modified":"2023-10-27T19:15:46","modified_gmt":"2023-10-27T23:15:46","slug":"u-of-m-data-breach-is-your-information-safe","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/u-of-m-data-breach-is-your-information-safe\/","title":{"rendered":"U of M Data Breach:  Is Your Information Safe"},"content":{"rendered":"\r\n<p><strong><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-129571 size-medium\" title=\"U of M Data Breach:  Is Your Information Safe\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/35a983ba-fbad-4ded-9323-75a4309e41aa-e1696269155200-150x119.jpg?resize=150%2C119&#038;ssl=1\" alt=\"U of M Data Breach:  Is Your Information Safe\" width=\"150\" height=\"119\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/35a983ba-fbad-4ded-9323-75a4309e41aa-e1696269155200.jpg?resize=150%2C119&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/35a983ba-fbad-4ded-9323-75a4309e41aa-e1696269155200.jpg?resize=75%2C60&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/35a983ba-fbad-4ded-9323-75a4309e41aa-e1696269155200.jpg?resize=768%2C609&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/35a983ba-fbad-4ded-9323-75a4309e41aa-e1696269155200.jpg?w=930&amp;ssl=1 930w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/>&#8211; Updated 10\/27\/2923 &#8211;<\/strong> This data breach compromised 230,000 individuals according to the <a title=\"Hackers gained access to personal info on up to 230,000 individuals, UM says\" href=\"https:\/\/www.detroitnews.com\/story\/news\/local\/michigan\/2023\/10\/23\/um-3rd-party-accessed-school-systems-personal-information-for-5-days\/71292044007\/\" target=\"_blank\" rel=\"nofollow noopener\">Detroit News<\/a>.<\/p>\r\n<p style=\"text-align: center;\">&#8212;<\/p>\r\n<p>If you attended the <strong>University of Michigan<\/strong>, your <strong>personal information is at risk<\/strong>. The media was full of <a title=\"University of Michigan shuts down school\u2019s internet connections following \u2018significant\u2019 cybersecurity incident\" href=\"https:\/\/www.cnn.com\/2023\/08\/29\/politics\/university-of-michigan-cyber-incident-offline\/index.html\" target=\"_blank\" rel=\"nofollow noopener\">stories about the U-M<\/a> <a title=\"Security concern leads to first day of UM classes with internet outage\" href=\"https:\/\/www.detroitnews.com\/story\/news\/local\/michigan\/2023\/08\/28\/internet-down-at-um-ann-arbor-dearborn-on-first-day-of-classes\/70699851007\/\" target=\"_blank\" rel=\"nofollow noopener\">networks being shut-down<\/a> at the beginning of the semester. Now we know at least one reason why. The U-M had to shut down its networks because the U.S. educational nonprofit <strong>National Student Clearinghouse<\/strong> (NSC) disclosed a data breach affecting UMich. The breach also impacted 890 other institutions using NSC services across the United States. Here is the <a title=\"Office of the California Attorney General\" href=\"https:\/\/oag.ca.gov\/system\/files\/Exhibit%20A_6.pdf\" target=\"_blank\" rel=\"nofollow noopener\">complete list<\/a>.<\/p>\r\n<p><a href=\"https:\/\/www.studentclearinghouse.org\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-129572 size-thumbnail\" title=\"National Student Clearinghouse\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NSC-e1696269644630-75x68.jpg?resize=75%2C68&#038;ssl=1\" alt=\"National Student Clearinghouse\" width=\"75\" height=\"68\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NSC-e1696269644630.jpg?resize=75%2C68&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NSC-e1696269644630.jpg?resize=150%2C135&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NSC-e1696269644630.jpg?w=611&amp;ssl=1 611w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>NSC said that attackers gained access to its MOVEit managed file transfer (MFT) server on May 30 and stole files containing a wide range of <strong>personal information<\/strong>. NSC reported the breach to the Office of the California Attorney General,<\/p>\r\n<p style=\"padding-left: 40px; text-align: center;\"><em>On May 31, 2023, the Clearinghouse was informed by our third-party software provider, Progress Software, of a cybersecurity issue involving the provider&#8217;s MOVEit Transfer solution<\/em><\/p>\r\n<h3>What personally identifiable information\u00a0<\/h3>\r\n<p><a href=\"https:\/\/anonyome.com\/2020\/05\/what-constitutes-personally-identifiable-information-or-pii\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-129575\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?resize=101%2C53&#038;ssl=1\" alt=\"\" width=\"101\" height=\"53\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?resize=150%2C79&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?resize=1024%2C538&amp;ssl=1 1024w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?resize=75%2C39&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?resize=768%2C403&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?w=1200&amp;ssl=1 1200w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pii3.jpg?w=960&amp;ssl=1 960w\" sizes=\"auto, (max-width: 101px) 100vw, 101px\" \/><\/a><a title=\"National Student Clearinghouse data breach impacts 890 schools\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/national-student-clearinghouse-data-breach-impacts-890-schools\/\" target=\"_blank\" rel=\"nofollow noopener\">According<\/a> to <a title=\"Bleeping Computer\" href=\"https:\/\/www.bleepingcomputer.com\" target=\"_blank\" rel=\"nofollow noopener\">Bleeping <em>Computer<\/em><\/a> the<strong> personally identifiable information<\/strong> (PII) stolen includes names, dates of birth, contact information, Also compromised were<strong> Social Security numbers<\/strong>, student ID numbers. Finally they report and some school-related records (e.g., enrollment records, degree records, and course-level data) were also stolen.<\/p>\r\n<h3>What is the National Student Clearinghouse\u00a0<\/h3>\r\n<p>The <a href=\"https:\/\/www.studentclearinghouse.org\/\" target=\"_blank\" rel=\"nofollow noopener\">National Student Clearinghouse<\/a> provides educational reporting, data exchange, verification, and research services. They provide services to roughly <strong>22,000 high schools and around 3,600 colleges and universities<\/strong>. The organization says its participants enroll roughly 97% of students in public and private institutions.<\/p>\r\n<h3>Who is behind the MoveIT data breach<\/h3>\r\n<p>The <a title=\"CISA and FBI Release Advisory on CL0P Ransomware Gang Exploiting MOVEit Vulnerability\" href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-and-fbi-release-advisory-cl0p-ransomware-gang-exploiting-moveit-vulnerability\" target=\"_blank\" rel=\"nofollow noopener\">Clop ransomware gang<\/a> is responsible for the extensive data-theft attacks that started on May 27. The attackers leveraged a zero-day security flaw in the MOVEit Transfer secure file transfer platform.<br \/><br \/>Starting June 15, the cyber criminals began extorting organizations that fell victim to the attacks, exposing their names on the group&#8217;s dark web data leak site. The cybercrime gang is expected to collect an estimated $75-100 million in payments due to the high ransom requests.<br \/><br \/>Reports have also revealed that multiple U.S. federal agencies and two U.S. Department of Energy (DOE) entities have fallen prey to MOVEit-related these data theft and extortion attacks.<\/p>\r\n<p>&nbsp;<\/p>\r\n<p style=\"text-align: center;\"><em><strong><a title=\"How You Can Help the People of Ukraine\" href=\"https:\/\/www.obama.org\/updates\/help-ukraine\/\" target=\"_blank\" rel=\"nofollow noopener\">How you can help Ukraine!<\/a><\/strong><\/em><\/p>\r\n<p><strong>Related article<\/strong><\/p>\r\n<ul>\r\n<li><a title=\"Michigan State University data breach linked to global ransomware attack\" href=\"https:\/\/www.lansingstatejournal.com\/story\/news\/2023\/08\/10\/data-breach-michigan-state-university-national-student-clearning-house-tiaa\/70565091007\/\" target=\"_blank\" rel=\"nofollow noopener\">Michigan State University data breach linked to global ransomware attack<\/a>\u00a0(<a title=\"Lansing State Journal\" href=\"https:\/\/www.lansingstatejournal.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Lansing State Journal<\/a>)<\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>\r\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>\u00a0about IT, careers, and anything else that catches his attention since 2005. You can follow him on\u00a0<a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>University of Michigan records could be involved in a nation-wide MOVEit data breach at National Student Clearinghouse<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[3652,125,3711,951,3710],"class_list":["post-129539","post","type-post","status-publish","format-standard","hentry","tag-3652","tag-data-breach","tag-moveit","tag-pii","tag-umich"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/129539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=129539"}],"version-history":[{"count":10,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/129539\/revisions"}],"predecessor-version":[{"id":129741,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/129539\/revisions\/129741"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=129539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=129539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=129539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}