Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
800,000 Students, Faculty Victims in Ongoing MOVEit Breach
Facebook   X   LinkedIn   Email

800,000 Students, Faculty Victims in Ongoing MOVEit Breach

July 3, 2024

Over 800,000 (and counting) students, faculty, and staff at the University System of Georgia (USG) are now part of the growing list of victims of a data breach within the education sector. The Russian-linked hacking group, Clop (aka cl0p), recently included USG in the ongoing year-long breach of MOVEit file transfer software and its clients. The personally identifiable information (PII) of more than 77 million people has been exposed in the wake of continuing attacks worldwide.

USG is the latest of more than 2,600 organizations victimized globally by the MOVEit breach. In particular, Clop’s MOVEit attacks focus on higher education and small-to-medium sized businesses (SMBs). Historically, both groups lack the resources needed for a strong cyber-defense, making them prime targets for ransomware and other devastating attacks.

According to findings by Emsisoft, the U.S. represents 78.1% of those affected by Clop’s massive and persistent MOVEit data breach. They note Canada is second behind the U.S. with 14% of attacks, Germany with 1.4% and the UK with 0.8%.

Education in The Crosshairs

Education in general is under attack by cybercriminals, with USG as one of the largest systems in the country. It represents 26 public universities and colleges and more than 333,000 students. According to USG, some of the hijacked PII includes names, physical and email addresses, phone numbers, Social Security numbers, salary and benefit data, among other highly sensitive information.

Emsisoft reports the education sector is most targeted by Clop’s MOVEit breach, representing 40.6% of all reported attacks. Other victims include the health sector at 19.2%, and professional and finance services at 12.1%. With education victims leading the pack, it’s a symptom of the ongoing trend of cyberattacks against these institutions.

Data Treasure Troves

File transfer services like MOVEit are increasingly targeted due to the vast amount of data their servers hold. Sensitive PII is a goldmine for hackers who use and/or sell the data for their own financial gain. The information-linked services offered by MOVEit and others like them gives incentive to attackers looking for a jackpot of lucrative information.

USG is notifying victims, offering them free credit monitoring, and identity protection services. Whenever free credit monitoring is offered, it’s a good plan to take advantage of it. Just remember that it won’t prevent someone from using the information for fraud; the service will merely alert you that someone is trying.

USG also immediately applied security patches available for the MOVEit flaw, but many organizations using the service have yet to follow suit. Waiting to use security patches is a lesson in “what not to do” taught in Cyber-Education 101. Class dismissed!


Financial Aid Fraud Tests Your Scam Radar

Scams & Phishing

Financial Aid Fraud Tests Your Scam Radar

It’s just about that time again where college-bound students are seeking big help so they can go to a college or university. And as we know, this is a very pricey endeavor, and many students are looking for financial help. Where there is money involved, there are cybercriminals doing their best to get to it, including trying to defraud students applying for financial aid. There are few ways, however, that you can identify if someone is trying to scam you, rather than help you out. READ FULL STORY

FBI Warns of Threat from North Korean APT

Corporate Security

FBI Warns of Threat from North Korean APT

A North Korean-linked APT (Advanced Persistent Threat) group recently found and exploited an email vulnerability. Documented in a joint advisory from the FBI, Department of State, and the National Security Agency (NSA), it warns of an issue with weak DMARC (Domain-based Message Authentication, Reporting & Conformance) Security policies that allow a backdoor malware. The advisory does not point to a specific threat to MacOS, but there are known instances of one called SpectralBlur. Though the advisory warns all operating systems are at risk. READ FULL STORY

TikTok Collects User Biometric Data, Risking Face And Voice Print Abuse

Mobile Security

TikTok Collects User Biometric Data, Risking Face And Voice Print Abuse

Like most electronic data, biometric data is permanent, and in this case it’s your unique voice and facial recognition prints being collected. Security experts are concerned about TikTok’s latest user data grab. The company recently announced they’re collecting new data on users from their video and audio files. Face and voice prints are now being collected from TikTok’s 689 million active global active users, currently without permission. READ FULL STORY

48% Of SMBs Have Rocky Road To Cybersecurity

Corporate Security

48% Of SMBs Have Rocky Road To Cybersecurity

Protecting your business from cyberattacks is a concern for every enterprise. Perhaps nowhere is that more evident than with small-to-medium sized businesses (SMBs). SMBs face a unique set of challenges to their cybersecurity that large corporations just don’t have. A global study of SMBs by Sage business software shares insights into the SMB security landscape. With cyberattacks expanding and evolving, survey highlights and helpful security tips are a must-read for all SMBs. READ FULL STORY

MOVEit Moves  To Colorado--Millions Affected In Recent Attacks

Identity Theft

MOVEit Moves To Colorado--Millions Affected In Recent Attacks

The Colorado Department of Health Care Policy and Financing (HCPF) has reported a breach that compromised the data of more than 4 million individuals. The incident was attributed to IBM, a vendor for the state, which utilizes the MOVEit application for the transfer of HCPF data files. Not standing alone, another organization impacted by this recent breach is Missouri’s Department of Social Services (DSS), which also uses IBM's services. MOVEit just won't move on. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...