Close to Quarter of Million People Were Vulnerable to Unauthorized Online Access at Western Connecticut State University

By Ed Silverstein November 29, 2012

Some 233,880 people who had contact with Western Connecticut State University were vulnerable to having their private records exposed to unauthorized online access, according to the Danbury, Conn., school.

The records include Social Security numbers and financial account information which date back 13 years. The vulnerability took place between April 2009 and September 2012.

The university claims it found no evidence that records were inappropriately accessed, and has corrected the vulnerability in the storage system.

The Ridgefield Press reported that the vulnerability was found in a security audit, not found out because of a data breach.

“It was a regular maintenance [discovery], kind of looking at the system,” Interim Associate Vice President Paul Steinmetz told the newspaper. “It was discovered by the University Computing — our IT department.”

It also appears the vulnerability was caused by a “misconfiguration, rather than a flaw in software licensed from a vendor,” Steinmetz told the newspaper.

The university has been proactive since the discovery.

“We are disappointed that these records were potentially exposed, but we will do everything we can to protect our students, their families and others with whom we have worked,” Western Connecticut President James W. Schmotter said in a recent statement. “The steps we are taking and the solutions we are offering to every one of those affected are designed to address any problems this situation may have caused.”

Those impacted include students, their relatives who filled out financial aid information, and others who associated with the university, as well as high school students whose SAT scores were purchased in lists by the college. 

The university is offering up to two years of ID theft protection at no cost through AllClear ID, according to a university statement.  AllClear ID provides free identity theft protection service for consumers, TechZone360 adds.

Western Connecticut also has set up a searchable database that contains the names of all affected individuals. A hotline at (855) 731-6012 was also set up to answer questions.




Edited by Rich Steeves

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

Verizon Needs Tough Love on Copper Policies

By: Doug Mohney    1/29/2015

New regulation on broadband and telecommunications providers is at top of mind here at ITEXPO. Jeff Pulver, founder and chief executive of pulver.com …

Read More

OTT Video Set to Top $6 Billion in 2019

By: Tara Seals    1/29/2015

When it comes to over-the-top (OTT) video, it has grown not only in developed regions but also in emerging markets, both as an alternative and complem…

Read More

Digium CEO: Businesses at Every Level Can Get Started with UCaaS

By: Allison Boccamazzo    1/29/2015

Digium CEO Danny Windham made one thing clear during his keynote presentation at ITEXPO 2015: Businesses of all kinds, at every developmental level, c…

Read More

When Gaming Isn't a Game: 3 Best Practices to Protect Your Hosting Service Against DDoS Attacks

By: Joe Eskew    1/28/2015

The unprecedented number of security breaches, hacks and DDoS attacks on gaming communities, software manufacturers and even Hollywood studios grew to…

Read More

No Hackers Took Down Facebook; Hour's Outage Mostly Internal

By: Steve Anderson    1/28/2015

Facebook released a statement not long after the outage had hit, revealing that the cause of the shutdown was not "...the result of a third-party atta…

Read More