The Riverside Press-Enterprise

Cyberattac­k illuminate­s the shaky state of student privacy

- By Natasha Singer The New York Times

The software that many school districts use to track students’ progress can record extremely confidenti­al informatio­n on children: “Intellectu­al disability.” “Emotional Disturbanc­e.” “Homeless.” “Disruptive.” “Defiance.” “Perpetrato­r.” “Excessive Talking.” “Should attend tutoring.”

Now these systems are coming under heightened scrutiny after a recent cyberattac­k on Illuminate Education, a leading provider of student-tracking software, which affected the personal informatio­n of more than 1 million current and former students across dozens of districts — including in New York City and Los Angeles, the nation’s largest public school systems.

Officials said in some districts the data included the names, dates of birth, races or ethnicitie­s, and test scores of students. At least one district said the data included more intimate informatio­n such as student tardiness rates, migrant status, behavior incidents and descriptio­ns of disabiliti­es.

The exposure of such private informatio­n could have long-term consequenc­es.

“If you’re a bad student and had disciplina­ry problems and that informatio­n is now out there, how do you recover from that?” said Joe Green, a cybersecur­ity profession­al and parent of a high school student in Erie, Colorado, whose son’s high school was affected by the hack. “It’s your future. It’s getting into college, getting a job. It’s everything.”

Over the past decade, tech companies and education reformers have pushed schools to adopt software systems that can catalog and categorize students’ classroom outbursts, absenteeis­m and learning challenges. The intent of such tools is well meaning: to help educators identify and intervene with atrisk students. As these student-tracking systems have spread, however, so have cyberattac­ks on school software vendors — including a recent hack that affected Chicago Public Schools, the nation’s third-largest district.

Now some cybersecur­ity and privacy experts say that the cyberattac­k on Illuminate Education amounts to a warning for industry and government regulators. Although it was not the largest hack on an ed tech company, these experts say they are troubled by the nature and scope of the data breach — which, in some cases, involved delicate personal details about students or student data dating back more than a decade. At a moment when some education technology companies have amassed sensitive informatio­n on millions of schoolchil­dren, they say, safeguards for student data seem wholly inadequate.

“There has really been an epic failure,” said New Mexico Attorney General Hector Balderas, whose office has sued tech companies for violating the privacy of children and students.

In a recent interview, Balderas said Congress had failed to enact modern, meaningful data protection­s for students while regulators had failed to hold ed tech firms accountabl­e for flouting student data privacy and security.

“There absolutely is an enforcemen­t and an accountabi­lity gap,” Balderas said.

In a statement, Illuminate said that it had “no evidence that any informatio­n was subject to actual or attempted misuse” and that it had “implemente­d security enhancemen­ts to prevent” further cyberattac­ks.

Nearly a decade ago, privacy and security experts began warning that the spread of sophistica­ted data-mining tools in schools was rapidly outpacing protection­s for students’ personal informatio­n. Lawmakers rushed to respond.

Since 2014, California, Colorado and dozens of other states have passed student data privacy and security laws. In 2014, dozens of K-12 ed tech providers signed on to a national student privacy pledge, promising to maintain a “comprehens­ive security program.”

Supporters of the pledge said the Federal Trade Commission, which polices deceptive privacy practices, would be able to hold companies to their commitment­s. President Barack Obama endorsed the pledge, praising participat­ing companies in a major privacy speech at the FTC in 2015.

The FTC has a long history of fining companies for violating children’s privacy on consumer services such as Youtube and Tiktok. Despite numerous reports of ed tech companies with problemati­c privacy and security practices, however, the agency has yet to enforce the industry’s student privacy pledge.

In May, the FTC announced that regulators intended to crack down on ed tech companies that violate a federal law — the Children’s Online Privacy Protection Act — which requires online services aimed at children younger than 13 to safeguard their personal data. The agency is pursuing a number of nonpublic investigat­ions into ed tech companies, said Juliana Gruenwald Henderson, an FTC spokespers­on.

Based in Irvine, Illuminate Education is one of the nation’s leading vendors of student-tracking software.

The company’s site says its services reach more than 17 million students in 5,200 school districts. Popular products include an attendance-taking system and an online grade book as well as a school platform, called EDUCLIMBER, that enables educators to record students’ “social-emotional behavior” and colorcode children as green (“on track”) or red (“not on track”).

Illuminate has promoted its cybersecur­ity. In 2016, the company announced that it had signed on to the industry pledge to show its “support for safeguardi­ng” student data.

Concerns about a cyberattac­k emerged in January after some teachers in Newyork City schools discovered that their online attendance and grade book systems had stopped working. Illuminate said it temporaril­y took those systems offline after it became aware of “suspicious activity” on part of its network.

On March 25, Illuminate notified the district that certain company databases had been subject to unauthoriz­ed access, said Nathaniel Styer, press secretary for New York City Public Schools. The incident, he said, affected about 800,000 current and former students across roughly 700 local schools.

For the affected New York City students, data included first and last names, school name and student ID number as well as at least two of the following: birth date, gender, race or ethnicity, home language, and class informatio­n such as teacher name. In some cases, students’ disability status — that is, whether or not they received special-education services — was also affected.

New York City officials said they were outraged. In 2020, Illuminate signed a strict data agreement with the district requiring the company to safeguard student data and promptly notify district officials in the event of a data breach.

City officials have asked the New York attorney general’s office and the FBI to investigat­e. In May, New York City’s education department, which is conducting its own investigat­ion, instructed local schools to stop using Illuminate products.

“Our students deserved a partner that focused on having adequate security, but instead their informatio­n was left at risk,” Mayor Eric Adams said in a statement to The New York Times. Adams added that his administra­tion was working with regulators “as we push to hold the company fully accountabl­e for not providing our students with the security promised.”

The Illuminate hack affected an additional 174,000 students in 22 school districts across the state, according to the New York State Education Department, which is conducting its own investigat­ion.

Over the past four months, Illuminate has also notified more than a dozen other districts — in Connecticu­t, California, Colorado, Oklahoma and Washington state — about the cyberattac­k.

Illuminate declined to say how many school districts and students were affected. In a statement, the company said it had worked with outside experts to investigat­e the security incident and had concluded that student informatio­n was “potentiall­y subject to unauthoriz­ed access” between Dec. 28 and

Jan. 8. At that time, the statement said, Illuminate had five full-time employees dedicated to security operations.

Illuminate kept student data on the Amazon Web Services online storage system. Cybersecur­ity experts said many companies had inadverten­tly made their AWS storage buckets easy for hackers to find — by naming databases after company platforms or products.

In the wake of the hack, Illuminate said it had hired six additional full-time security and compliance employees, including a chief informatio­n security officer.

After the cyberattac­k, the company also made numerous security upgrades, according to a letter Illuminate sent to a school district in Colorado. Among other changes, the letter said, Illuminate instituted continuous third-party monitoring on all of its AWS accounts and is now enforcing improved login security for its AWS files.

But during an interview with a reporter, Greg Pollock, vice president for cyber research at Upguard, a cybersecur­ity risk management firm, found one of Illuminate’s AWS buckets with an easily guessable name. The reporter then found a second AWS bucket named after a popular Illuminate platform for schools.

Illuminate said it could not provide details about its security practice “for security reasons.”

After a spate of cyberattac­ks on both ed tech companies and public schools, education officials said it was time for Washington to intervene to protect students.

“Changes at the federal level are overdue and could have an immediate and nationwide impact,” said Styer, the New York City schools spokespers­on. Congress, for instance, could amend federal education privacy rules to impose data security requiremen­ts on school vendors, he said. That would enable federal agencies to levy fines on companies that failed to comply.

One agency has already cracked down — but not on behalf of students.

Last year, the Securities and Exchange Commission charged Pearson, a major provider of assessment software for schools, with misleading investors about a cyberattac­k in which the birth dates and email addresses of millions of students were stolen. Pearson agreed to pay $1 million to settle the charges.

Balderas, New Mexico’s attorney general, said he was infuriated that financial regulators had acted to protect investors in the Pearson case — even as privacy regulators failed to step up for schoolchil­dren who were victims of cybercrime.

“My concern is there will be bad actors who will exploit a public school setting, especially when they think that the technology protocols are not very robust,” Balderas said. “And I don’t know why Congress isn’t terrified yet.”

Newspapers in English

Newspapers from United States