Info-Sec fail on a grand scale
hive-193212·@bozz·
25.859 HBDInfo-Sec fail on a grand scale
<center></center> --------------------- I've mentioned before that I work for a small public school district in the United States. As you might imagine, information security is one of the biggest things that keeps me up at night. I remember reading a study quite some time ago about identity theft and the fact that a majority of ID theft happens to kids. Usually, it's a family member who has exhausted all the obvious resources, so they then turn to their children who have pristine credit. Imagine gaining access to hundreds if not thousands of fresh and clean identities. Believe it or not, back in the day some school districts used the students social security number as their unique identifier. Thankfully, most districts have moved away from that as of a couple decades ago, but you can see something like that could be a problem. I would venture to guess most school districts in the world use some kind of Student Information System (SIS) to store their data. These pieces of software store things like basic information, grades, attendance, discipline records and all sorts of other information. It's basically a large database like most other things in the world with a pretty front end. That actually describes about 80% of the Internet actually: ## A database with a pretty front end While businesses and hospitals have always been prime targets for nefarious individuals or groups of bad actors, in the last five years schools have raced to the top of the list of high value targets. There are a couple reasons for this. First, as I mentioned already, schools have a huge amount of PID (personal identifiable information) on students. This info is huge for marketing, or other more sinister endeavours. Second, despite what a lot of people think, most public schools are severely underfunded. This means that they often have less or low quality security measures protecting this most sensitive data. <center></center> ----------------------- There is a wide range of companies that offer SIS systems as a service. Some of them host the data for you, some allow you to run the software on your own servers, it's pretty standard practice. Among that wide range of vendors, there are a couple who have a larger share of the market than others. One such vendor goes by the name of Powerschool. Thankfully, this isn't the company we use, but a data breach in late 2024, led to the extortion of the company by the ransomware group. The one good thing that came out of this was it prompted most other vendors and end users to reevaluate the security of their given SIS and hopefully it will eliminate this attack vector in the future. If you are curious about the scope of something like this, [according to the Internet](https://www.techtarget.com/whatis/feature/PowerSchool-data-breach-Explaining-how-it-happened), Powerschool serves over 18,000 school organizations across 90 countries. Thankfully, we are not one of them! As scary as this all sounds, believe it or not, it gets even crazier. So the hack in late 2024 happened because Powerschool used (they don't anymore) a third party company to handle their support calls. It seems one of the employees at the support company was using easily compromised credentials and this basically gave the attackers a backdoor into many databases. They then proceeded to pull as much data as they could from every database they could access which included personal info of students and staff. A multi-million dollar ransom was demanded from Powerschool to not disclose the data which the company ended up paying. Wouldn't you know it though, after the ransom was paid and everyone thought this was over, the attacker started reaching out to individual school districts also demanding ransom from them. Shocker! Unlike most incidents like this, the Department of Justice actually found the bad actor who happened to be a 19 year old student at a university in Massachusetts. They don't believe he was working alone, but as of now he made a plea deal and is going to be spending about ten years in prison. It almost makes you wonder if he had just taken the initial money and run without trying to extort the actual school districts if he would have been able to get away with it. With most everything moving to Software as a Service (SaaS) these days, we trust that our data is being kept safe by the companies we are paying obscene fees to use their software. This is just a good example of how something relatively benign and easy to overlook can turn into something much larger. It's more important than ever to do what you can to keep your data safe. ---------- <center> ### [My Sports Account - @bozz.sports](https://www.peakd.com/@bozz.sports) </center> ---------- <center></center> ---------- <center>*All pictures/screenshots taken by myself or @mrsbozz unless otherwise sourced*</center>
👍 isnochys, buggedout, smartvote, cryptictruth, sumatranate.leo, slickwilly, scaredycatguide, sumatranate, critic-on, dbooster, epic-fail, skylinebuds, aiuna, scaredycatcurate, babytarazkp, khalstem, thisismylife, whywhy, finguru, brofi, thebighigg, glimpsytips.dex, vaclavs, legionsupport, gifu, sepone, slider2990, valchiz, upfundme, therabbitzone, bozz.sports, bilpcoin.pay, officialhisha, leoschein, gualteramarelo, megaleoschein, dugsix, phul, bhealy, darinapogodina, maurofolco, zwhammer, solominer.leo, tub3r0, vyb.curation, fredaig, trumpybear, neal.power, wearelegion, solfart, michael561, coffee-lovers, rok-sivante, muntaharaceh, dwinblood, richardcrill, dalz.shorts, emsenn0, flamistan, funshee, iproto, tengolotodo, khoola, trostparadox.vyb, venarisyndicate, crazygirl777, bungongjaro, leprechaun, steemexperience, lordnasty, vyb.pob, monzo, coffeebuds, proofofbrainio, patientgamer9, saboin.pob, anacristinasilva, smokingfit, holoferncro, drricksanchez, shanhenry, beardoin, netaterra, xurph, mineopoly, phortun, erikah, therealyme, netaterra.leo, sbi2, mcsagel, hairyfairy, b00m, spamfarmer, bluepluto, dimascastillo90, cur8, cryptoandcoffee, teutonium, sbi-tokens, artjohn, upvoteshares, meppij, philnewton, bdmillergallery, iamfarhad, eds-vote, noloafing, sneakyninja, thedailysneak, babysavage, ravensavage, iikrypticsii, dab-vote, coolguy123, successchar, jilt, ifarmgirl, noctury, eolianpariah2, cocaaladioxine, radard, armentor, ifarmgirl-leo, enginewitty, nuthman, thealliance, bigtom13, blanchy, unbiasedwriter, victor-alexander, axel-blaze, im-ridd, iamcyril, gallatin, clubvote, duo-curator, hoosie, elizacheng, jayna, burkulese, rumplestiltskin, anomallies, emjoe, bengy, antdroid, khimgoh, break-out-trader, ashley4u, lunamoon, khaldeesi, freyamber, angeltree, christmasclub, wittys.angels, wittysangels, angiel, sassafrass, clifth, dhedge, cantfoldaces, brucegryllis, karina.yana, dadview, bitcoinman, dabeckster, gohba.handcrafts, vm2904, summertooth, felt.buzz, michaeldavid, vikar, splash-of-angs63, steemitcomics, brisby, themothership, platosgroove, psyborg, hazem91, katrina-ariel, joseantpp, monchhichi23, thejollyroger, allied-mafia, steemforschool, steemforschools, tinyhousecryptos, alliedbanking, birthdaywishes, hive-123585, communityunity, barbyjr, ismaelrd04, bellelynn, tergan604, b34w0lf, timmy-turnip, jaydr, dirego1, iwannabeme, willendorfia, monkeymanking, moeknows, tyedyefirepower, cygon, musicapoetica, veteranforcrypto, thealliancebank, alliedfun, bobthebuilder2, arc7icwolf, thekrazypoet, actordontee, whitneyalexx, franco10, dook4good, brofund-witness, stickupcurator, javeson, dailydab, mamadini, raj808, oadissin, robvector, hmvf, theluvbug, thepatriotblog, killerwhale, syndicates, a11y, tygertyger, alliedforces, x40l1n, fambalam, newigennity, plusvault, theblockpartyii, toekins, w1tty, assistance, nism, thetradecenter, blemish, pixelfan, chaosmagic23, thesummoner, r-e-d, lord-of-the-d, steemforsteem, toonuts, twonuts, letlove, itwasme, theblooded, blooded, theclan, youdo, bi0digital, chaos23, tokencav, solominer, freebornsociety, whangster79, recoveryinc, samrisso, tomtothetom, movement19, silvergoldbotty, chain.games, publicview, sports.power.bot, pobscholarship, ambiguity, edthecanadian, dr460n3y3, vetfunding, vindiesel1980, patronpass, marjanko, jfuji, silverstackeruk, voxmortis, spinvest, eddie-earner, spi-store, thebigfish, underground, hivedrip, thorlock, mighty-thor, slobberchops, cmmndrbawang, dwixer, hive-193566, freedomring, hive-165007, lakawero, acantoni, slothlydoesit, slothbuzz, fiftysixnorth, cconn, tomwafula, minerspost, darkpylon, aliz7575, dreemsteem, sku77-poprocks, merit.ahama, davidbright, blocktunes, saffisara, wildo, slothburn, vyb.fund, princessmewmew, thistle-rock, shadowspub, crescendoofpeace, haveyaheard, soyrosa, nateaguila, deadgrlsuppastar, simgirl, afifa, fieryfootprints, thelogicaldude, byn, cryptofairy, progressivechef, christianyocte, crazydaisy, pladozero, tattoodjay, friendmoose.pob, penguinpablo, cryptonized, funnyman, alphacore, hungrybear, guysellars, jacuzzi, c0ff33a, nolasco, snowpea, ilhuna, blue.panda, whiterosecoffee, the.lazy.panda, hivelist, ganjafarmer, joeyarnoldvn, teamuksupport, fazendadolobo, cryptosneeze, tommys.shop, azamsohrabi, nonsowrites, abh12345, racibo, mattbrown.art, jasonbu, methodofmad, tryskele, leaky20, sarawutthai, appreciator, flemingfarm, detlev, bluemist, sunsea, dynamicrypto, kkarenmp, danielcarrerag, bertrayo, ravenmus1c, inciter, manuelmusic, marblely, miguelbaez, alenox, discoveringarni, lucianav, gabilan55, noalys, omarcitorojas, elgatoshawua, hexagono6, power-kappe, fotomaglys, seryi13, cesarsj5, aprasad2325, liveofdalla, pinkchic, abu78, malhy, noelyss, marblesz, david.dicotomia, kattycrochet, tahastories1, vixmemon, nucleus-tezz, darth-azrael, darth-cryptic, retrodroid, shanibeer, beerlover, bluefinstudios, godfish, petrvl, espoem, photoparadise, zirky, nikdo, actifit-godfish, belahejna, maajaanaa, collinz, krakatice, steevc, marsupia, soundminds, lisfabian, jane1289, ericvancewalton, wiseagent, davedickeyyall, awakening-along, nvstly, valerianis, gwajnberg, hivepakistan, itwithsm, eunice9200, fashtioluwa, mishkatfatima, guiltyparties, jjerryhan, lifeskills-tv, cwow2, amberkashif, ak08, faiza34, ukrajpoot, hajime711, foodchunk, fredaa, rishagamo, hadianoor, jahanzaibanjum, meritocracy, quduus1, ayesha-malik, nyxlabs, leighscotford, almi, revisesociology, bpcvoter3, ninnu, revise.spk, enforcer48, admiralbot, aninsidejob, steemflagrewards, memehub, steemseph, nftspecialists, nathanpieters, mayt, agmoore2, silverd510, arieswilly, xsgreen-cook, arahman, akteveo, mytechtrail, rin-rin, jemsss.art, ahlawat, carolinawnn, softa, txerritxoa, ubasi, nevio104, fengchao, soumaren, social, haikurator, silingsi, zhaoyiseng, otsoak, shayaiykram, ukulima, hivebuzz, lizanomadsoul, manncpt, jnmarteau, pinmapple, roelandp, discovereurovelo, fronttowardenemy, xsasj, itchyfeetdonica, greddyforce, musicandreview, itsmikyhere, kimzwarch, gabrielatravels, vcclothing, arcange, achimmertens, laruche, xlety, calebmarvel24, walterjay, sorin.cristescu, orlandumike, louis00334, michupa, elderdark, beffeater, roozeec, steemitboard, marivic10, kachy2022, ksteem, holovision.stem, spiritabsolute, joanstewart,