Data breach at Indiana University may affect 146,000 students

  • 26 February 2014
  • 3 replies
  • 950 views

Userlevel 7
Badge +54
The personal data of 146,000 students and recent graduates of Indiana University, including their social security numbers and addresses, may have been exposed during a data breach, the university said in a statement.
Among those affected are people who attended the university from 2011 to 2014 at seven of its campuses, it said late on Tuesday.

"The information was not downloaded by an unauthorized individual looking for specific sensitive data, but rather was accessed by three automated computer data-mining applications, called webcrawlers, used to improve Web search capabilities," it said.
The university found last week that the data had been stored in an insecure location for the past 11 months. It then locked down the site and moved the data to a secure server the following day, it said.

The university notified the state's attorney general about the breach. It also set up an information hotline and a website to assist those concerned their data may have been exposed.
 
Source Article

3 replies

Userlevel 7
Badge +56
That is crazy that they had that data on a web crawlable location.  I think it's time for some EU-style data protection laws.  That might scare some organizations into getting more serious about security.
Userlevel 7
Nic, that may help but even over here, with the laws that we have, we are far from immune from this sort of thing...and trying to police it is a never ending struggle.  And I think that it is the same im most European countries that have similar DP laws.
 
But that is not a reason to try...I suppose!
Userlevel 7
Badge +56
@ wrote:
Nic, that may help but even over here, with the laws that we have, we are far from immune from this sort of thing...and trying to police it is a never ending struggle.  And I think that it is the same im most European countries that have similar DP laws.
 
But that is not a reason to try...I suppose!
True, the laws aren't a magic bullet.  But if there are penalties on the books then at least they'll try to do a bit better and do some auditing, hopefully 🙂

Reply