Close to Quarter of Million People Were Vulnerable to Unauthorized Online Access at Western Connecticut State University

By Ed Silverstein November 29, 2012

Some 233,880 people who had contact with Western Connecticut State University were vulnerable to having their private records exposed to unauthorized online access, according to the Danbury, Conn., school.

The records include Social Security numbers and financial account information which date back 13 years. The vulnerability took place between April 2009 and September 2012.

The university claims it found no evidence that records were inappropriately accessed, and has corrected the vulnerability in the storage system.

The Ridgefield Press reported that the vulnerability was found in a security audit, not found out because of a data breach.

“It was a regular maintenance [discovery], kind of looking at the system,” Interim Associate Vice President Paul Steinmetz told the newspaper. “It was discovered by the University Computing — our IT department.”

It also appears the vulnerability was caused by a “misconfiguration, rather than a flaw in software licensed from a vendor,” Steinmetz told the newspaper.

The university has been proactive since the discovery.

“We are disappointed that these records were potentially exposed, but we will do everything we can to protect our students, their families and others with whom we have worked,” Western Connecticut President James W. Schmotter said in a recent statement. “The steps we are taking and the solutions we are offering to every one of those affected are designed to address any problems this situation may have caused.”

Those impacted include students, their relatives who filled out financial aid information, and others who associated with the university, as well as high school students whose SAT scores were purchased in lists by the college. 

The university is offering up to two years of ID theft protection at no cost through AllClear ID, according to a university statement.  AllClear ID provides free identity theft protection service for consumers, TechZone360 adds.

Western Connecticut also has set up a searchable database that contains the names of all affected individuals. A hotline at (855) 731-6012 was also set up to answer questions.




Edited by Rich Steeves

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

GENBAND & Sonus Go Dutch for Merger

By: Maurice Nagle    5/23/2017

Mergers and acquisitions are the norm in business. However, it's not every day that two major cloud communications players with highly complementary o…

Read More

The Killer App for VR: The Ability to Meet Yourself

By: Rob Enderle    5/23/2017

I was at a VR event this week, and I'm sure the speaker misspoke when he said that one of the benefits of VR is the ability to meet yourself. But the …

Read More

WannaCry Ransomware Holds Files Hostage: Best Practices to Avoid Being a Victim

By: Special Guest    5/23/2017

More than 200,000 computers in more than 150 countries were crippled by a massive ransomware attack, dubbed WannaCry, and security experts warned that…

Read More

LeoSat Secures Japanese Investment for Enterprise Broadband Satellite Network

By: Doug Mohney    5/23/2017

Another broadband satellite cloud network moved closer to reality this month, with LeoSat securing an investment from SKY Perfect JSAT (SJC) Corporati…

Read More

Organizations Can Combat WannaCry & Jaff Ransomware With Well Instrumented DNS

By: Special Guest    5/22/2017

The Infoblox Intelligence Unit observed two global malware outbreaks on Friday, May 12. Although there is no indication that the two attacks were rela…

Read More