Western Connecticut Uncovers Security Hole; 234,000 Have Data Exposed

Western Connecticut State University has begun the arduous process of notifying its campus community by mail about a data exposure that lasted for more than three years. The challenge is compounded by the fact that a number of those affected have never had any direct relationship with the campus. Administrators said they didn't believe that anybody's personal information was accessed. However, the university is offering up to two years of free identity protection services to those who might be affected.

According to information issued in late November, a storage system vulnerability existed from April 2009 to September 2012, potentially exposing information that included Social Security numbers and financial account information for about 234,000 people. The records involved had been collected over a 13-year period and included students, their families, and others with a campus affiliation. It also included the data of high school students whose SAT scores had been compiled into marketing lists rented by the university, whether or not those students had ever contacted the university.

When the exposure came to light in September, the university communicated with its Board of Regents Information Security & Policy Office to conduct an investigation of the incident in order to determine what had happened and how it would affect those whose data was maintained in the affected storage system. The university also contacted the state Office of the Attorney General for help in determining how to proceed. Following the investigation, the university began sending notices of the exposure to affected people.

"We are disappointed that the potential existed to have these records exposed but we will do everything we can to protect our students, their families and others with whom we have worked," said President James Schmotter. "The steps we are taking and the solutions we are offering to every one of those affected are designed to address any problems this situation may have caused."

Western Connecticut U has set up a hotline to answer calls and also "dramatically increased its information protection capacity with new layers of protection," the institution stated in a frequently asked questions page.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • student reading a book with a brain, a protective hand, a computer monitor showing education icons, gears, and leaves

    4 Steps to Responsible AI Implementation

    Researchers at the University of Kansas Center for Innovation, Design & Digital Learning (CIDDL) have published a new framework for the responsible implementation of artificial intelligence at all levels of education.

  • glowing digital brain interacts with an open book, with stacks of books beside it

    Federal Court Rules AI Training with Copyrighted Books Fair Use

    A federal judge ruled this week that artificial intelligence company Anthropic did not violate copyright law when it used copyrighted books to train its Claude chatbot without author consent, but ordered the company to face trial on allegations it used pirated versions of the books.

  • server racks, a human head with a microchip, data pipes, cloud storage, and analytical symbols

    OpenAI, Oracle Expand AI Infrastructure Partnership

    OpenAI and Oracle have announced they will develop an additional 4.5 gigawatts of data center capacity, expanding their artificial intelligence infrastructure partnership as part of the Stargate Project, a joint venture among OpenAI, Oracle, and Japan's SoftBank Group that aims to deploy 10 gigawatts of computing capacity over four years.

  • laptop displaying a phishing email icon inside a browser window on the screen

    Phishing Campaign Targets ED Grant Portal

    Threat researchers at cybersecurity company BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.