Close to Quarter of Million People Were Vulnerable to Unauthorized Online Access at Western Connecticut State University

By Ed Silverstein November 29, 2012

Some 233,880 people who had contact with Western Connecticut State University were vulnerable to having their private records exposed to unauthorized online access, according to the Danbury, Conn., school.

The records include Social Security numbers and financial account information which date back 13 years. The vulnerability took place between April 2009 and September 2012.

The university claims it found no evidence that records were inappropriately accessed, and has corrected the vulnerability in the storage system.

The Ridgefield Press reported that the vulnerability was found in a security audit, not found out because of a data breach.

“It was a regular maintenance [discovery], kind of looking at the system,” Interim Associate Vice President Paul Steinmetz told the newspaper. “It was discovered by the University Computing — our IT department.”

It also appears the vulnerability was caused by a “misconfiguration, rather than a flaw in software licensed from a vendor,” Steinmetz told the newspaper.

The university has been proactive since the discovery.

“We are disappointed that these records were potentially exposed, but we will do everything we can to protect our students, their families and others with whom we have worked,” Western Connecticut President James W. Schmotter said in a recent statement. “The steps we are taking and the solutions we are offering to every one of those affected are designed to address any problems this situation may have caused.”

Those impacted include students, their relatives who filled out financial aid information, and others who associated with the university, as well as high school students whose SAT scores were purchased in lists by the college. 

The university is offering up to two years of ID theft protection at no cost through AllClear ID, according to a university statement.  AllClear ID provides free identity theft protection service for consumers, TechZone360 adds.

Western Connecticut also has set up a searchable database that contains the names of all affected individuals. A hotline at (855) 731-6012 was also set up to answer questions.




Edited by Rich Steeves

TechZone360 Contributor

SHARE THIS ARTICLE
Related Articles

The FCC's Big Net Neutrality Day

By: Peter Bernstein    2/27/2015

I am going to admit to being surprised by the U.S. Federal Communications Commission's (FCCs) Open Internet decision. FCC Chairman Tom Wheeler's new n…

Read More

FCC Vote Endorses Title II Approach to Net Neutrality

By: Paula Bernier    2/26/2015

After months of debate and the collection of comments from four million Americans, the Federal Communications Commission today voted on - and approved…

Read More

Frontier Customers Get DVR-Driven Free and Web TV

By: Bob Wallace    2/26/2015

In what could be a match made in cord cutter heaven, Frontier Communications said it will bundle the TiVo Roamio OTA DVR with its high-speed data serv…

Read More

Secure Shell Key Management in Light of OpenSSL Vulnerabilities: Part 1

By: TMCnet Special Guest    2/25/2015

Ever since computers started connecting to each other, people have been thinking about how to keep information on them secure. As the Internet evolved…

Read More

Title II Proposal Brings Certainty - and Questions

By: TMCnet Special Guest    2/24/2015

Over the past few months, there has been a lot of uncertainty surrounding the broadband industry in the United States due to Title II reclassification…

Read More