Minnesota Department of Education files, including some student data, were accessed as part of a large-scale and global cybersecurity attack on a file-transfer system, the state agency said Friday.
The hack by the Russian Cl0p ransomware syndicate exploited a program called MOVEit that is widely used by organizations to securely share files. The parent company of MOVEit's U.S. maker, Progress Software, alerted customers to the breach May 31 and issued a patch. But cybersecurity researchers say scores if not hundreds of companies may by then have had sensitive data quietly exfiltrated.
Initial data-theft victims also include the BBC, British Airways and Nova Scotia's government. The Minnesota Department of Education (MDE) said 24 of its files were affected.
According to MDE, the accessed files contained the names, dates of birth and counties of residence of 95,000 students placed in foster care throughout the state.
They also included information about:
- 124 students in the Perham School District who qualified for Pandemic Electronic Benefits Transfer (P-EBT). That data included student name, date of birth and in some cases home addresses.
- 29 students who were taking PSEO classes at Hennepin Technical College in Minneapolis. That data included student name, date of birth, address and high school and college transcript information containing the last four digits of the student's social security number.
- The names of five students on one Minneapolis Public Schools bus route.
By the time MDE heard about the vulnerability of the MOVEit file-transfer service on May 31, the files had already been accessed, said MDE spokesman Kevin Burns. As soon as the vulnerability was identified, MDE and Minnesota IT Services took "immediate steps" to prevent any further unauthorized access and began investigating the impact of the breach.
No financial information was included in the breached files, but MDE is recommending that those who had their data accessed take precautions, including monitoring their credit reports. Agency staff is working to notify people whose data was accessed and letters have been sent to hundreds of families, Burns said.
No virus or other malware was uploaded to MDE's hardware systems and, as of Friday, none of the information had been posted online, Burns said.