The Topeka Capital-Journal

Data breach affects college students

- Krystal Nurse

A data breach affecting nearly 200 colleges and universiti­es is causing some students to feel uneasy as the semester starts and experts urge them to safeguard their informatio­n and credit.

Progress, a software developmen­t company, announced in May that unauthoriz­ed users exploited vulnerabil­ities in its MOVEit Transfer and MOVEit Cloud programs. The company released a security update days later, but not before Cl0p, a hacker group, gained unauthoriz­ed access to people’s personal informatio­n, the U.S. Department of Homeland Security announced in June.

The breach particular­ly hit higher education institutio­ns, as they tend to use multiple second-party websites to offer health insurance for students, such as UnitedHeal­thcare, and to verify people’s degrees, such as the nonprofit National Student Clearingho­use. Those two websites rely on the MOVEit software to relay informatio­n to higher education institutio­ns about current and past students.

KonBriefin­g, a market research company focused on informatio­nal technology, said the ransomware attack affected an estimated 179 colleges and universiti­es in 41 states as of last week. The attack happened weeks after College Decision Day, May 1, and in between college graduation­s, impacting current and former students.

The National Student Clearingho­use said on its website informatio­n from past and current students’ records could’ve been exposed. UnitedHeal­thcare Student Resources said in July, a combinatio­n of students’ birthdays, ID numbers, Social Security numbers and insurance informatio­n may have been exposed. Both UnitedHeal­thcare and National Student Clearingho­use said security updates were made to the systems.

Michigan State University students recently told USA TODAY their perception­s of how well the university manages their informatio­n has changed because of the breach. Many learned about it in the fall despite the university’s July alert.

Gabby Sabo, 20, said she had no choice but to give MSU her Social Security number, financial informatio­n, address and birthday during the applicatio­n and enrollment process. She doesn’t know if the breach affected her, but it eroded the trust she has in higher education.

“They should do a better job because they have a lot of informatio­n on everyone because you have to give your social security number,” Sabo said.

Charles Cabell, 19, said he doesn’t know if his informatio­n was accessed, but wouldn’t be surprised as “everything is at your fingertips” with the internet.

Cabell has been in “many minor data breaches,” including Facebook’s 30 million-person hack in 2018 and Equifax’s 145 million-person breach in 2017, he said.

Progress’ breach exposed personal info about students

Progress doesn’t know what data was accessed in the attack because MOVEit Transfer is an on-premise software that runs on its clients’ computers, according to MOVEit’s informatio­n page. Spokespers­on John Eddy equated it to a person having a Windows computer, but Microsoft doesn’t see what files are installed.

The U.S. Department of Education said all affected institutio­ns were alerted about the incident more than two months ago. A spokespers­on told USA TODAY the department monitors and tracks cybersecur­ity incidents, but declined questions about how often the incidents occur.

In its 2023 Cost of Data Breach report, IBM said breaches so far cost the education industry $3.65 million this year, down from $3.86 million in 2022.

“People could try to take out loans using that informatio­n, attack bank accounts depending on what they have about you and socially engineer you and impersonat­e you,” said Fred Scholl, a cybersecur­ity professor at Quinnipiac University in Connecticu­t.

A class-action lawsuit has been filed against Progress for what filers alleged is negligent handling of personal data in Massachuse­tts. Progress declined to comment on the lawsuit.

UnitedHeal­thcare said affected people will receive a form of credit monitoring and identity theft protection services. National Student Clearingho­use has no mention of similar offerings on its website.

Experts: Monitor your credit, password usage

Class-action lawsuits could hold businesses accountabl­e if a court finds them negligent. But Scholl said people don’t have to wait to perform basic security checks on their banking and social media accounts.

“To some extent, individual­s have to be their own human firewall to protect their data,” he said.

To do that, Charles Henderson, head of IBM’s XForce, a data security response team, said people should set up a password manager and store all passwords in it. He said many will alert users if a website has been involved in a data breach and prompt people to change their passwords. However, he said many people fall victim to reusing passwords, which he classified as a massive security issue.

Experts have advised people to turn on and use two-factor authentica­tion wherever possible.

Newspapers in English

Newspapers from United States