Michigan State Grapples with Data Breach in Third-Party Software

keyboard with credit card and lock

Even as schools are dealing with the fallout from coronavirus, a Michigan university is facing the fallout of a cybersecurity virus too. Michigan State University said a data breach that hit one of its software vendors has affected about 300 people who processed credit card payments through its ecommerce site, shop.msu.edu.

Volusion, which provides online payment processing to companies, publicly reported that the personal information of some of its merchant clients was exposed last fall, when malware was inserted into its ecommerce application. An outside forensic evaluation uncovered the extent of the breach. Those affected were people who shopped on Volusion-hosted websites between Sept. 7 and Oct. 8, 2019, including one run for Michigan State.

According to university officials, the breach exposed names, phone numbers, addresses, credit card numbers, expiration dates and CVVs. In response, the institution said it would replace the payment solution with another "with stronger and more robust cybersecurity measures."

"While there was no breach to [our] networks or systems, this breach of a third-party vendor is concerning and compels us to do what we can to help those impacted by sharing this important information," noted Chief Information Officer Melissa Woo, in a statement. "We know that the best tool in protecting yourself from identity theft and preserving your personal information is accurate information and swift action."

The school also provided basic guidance on how to protect themselves in the face of a breach, including using two-factor authentication with online accounts where possible, taking advantage of free credit reporting and putting a fraud alert on personal credit files, as advised by the Federal Trade Commission.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • Blurred silhouettes of business people in a modern office with a glowing blue network overlay

    Open Secure AI Alliance Moves to Linux Foundation

    The Open Secure AI Alliance has moved under the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

  • Digital Screen with young woman using a virtual reality headset

    Montclair State U Partners with Dreamscape Learn on New VR Facility

    New Jersey's Montclair State University has announced the completion of a new virtual reality learning facility developed in partnership with Dreamscape Learn. The 2,450-square-foot lab space is inside the College of Communication and Media building and will serve students pursuing careers in digital media, virtual reality, and content creation.

  • closeup of hands using smart phone

    Learning Continuity Built into the LMS Withstands Cloud or Cybersecurity Interruptions

    When your institution's administrative or instructional capabilities face disruption from natural, technical, or malicious events, what measures does your LMS offer to provide a "business as usual" operating and learning environment? Instructure's Ryan Lufkin comments on the LMS and learning continuity.

  • artificial intelligence on laptop

    OpenAI to Combine AI Products into Desktop 'Superapp'

    OpenAI is reportedly developing a desktop application that would combine several of its emerging AI products into a single platform, according to reports, marking the latest step in the company's effort to transform ChatGPT from a standalone chatbot into a broader productivity and automation environment.