Data Breaches in US Schools Exposed 37.6M Records

Since 2005, educational institutions in the United States have experienced 3713 data breaches, impacting over 37.6m records.
According to new data by Comparitech, 2023 marked a record year, with 954 breaches recorded - a dramatic rise from 139 in 2022 and 783 in 2021.
This surge was primarily attributed to MOVEit file transfer software vulnerabilities, affecting over 800 institutions.
The number of records compromised in 2023 soared to nearly 4.3m, compared to approximately 2.6m in both 2021 and 2022.
Among these, 1.7m records were compromised in third-party breaches, and 1.9m were affected by 65 ransomware attacks.
The Comparitech research, analyzing data from the past 19 years, identified key trends and hotspots for breaches in the education sector.
Colleges and universities accounted for 60% of breaches, largely due to the MOVEit incident, and 83% of affected records originated from post-secondary institutions.
Cyber-attacks and ransomware have become the predominant causes of breaches, with third-party breaches also increasing due to significant incidents like those involving Blackbaud, Illuminate Education and MOVEit.
The MOVEit breach alone impacted at least 802 educational institutions.
The 2018 regulation changes by the US Department of Education mandated Title IV institutions to report any breach, regardless of the number of records affected, enhancing transparency.
The largest breaches of 2023 included the University System of Georgia, which reported that 800,000 individuals were impacted by the MOVEit exploit.
In terms of state impact, New York reported the highest number of breaches, with California following at 401.
California also had the largest number of records affected at more than 3.3m, closely followed by Arizona with nearly 2.9m. Texas led in K-12 student records breached, with over 1.7m records compromised.
Ransomware attacks predominantly hit K-12 schools, with 149 out of 246 tracked incidents since 2018 affecting this sector.
Despite this, post-secondary institutions saw a higher volume of records impacted by such attacks, with 3.74m records breached compared to 1.53m in K-12 schools.
North Dakota reported the highest rate of student records impacted per capita.
The top ten biggest breaches included notable incidents like the Maricopa County Community College District in 2013, affecting 2.49m records, and the Harvard Computer Society breach in 2017, impacting 1.4m records.
Other significant breaches involved institutions like Georgia Tech and the University of California at Los Angeles.
In 2024, the first quarter saw a significant reduction in breaches, with only 16 incidents reported between January and March, affecting 58,400 records, suggesting a potential positive trend.
The long-term outlook remains uncertain as cyber-attacks continue to evolve.


This Cyber News was published on www.infosecurity-magazine.com. Publication date: Tue, 14 May 2024 16:30:32 +0000


Cyber News related to Data Breaches in US Schools Exposed 37.6M Records

Cybersecurity in K-12 Schools - As technology becomes increasingly integrated into K-12 schools, the need for robust cybersecurity measures has never been more critical. By raising awareness and providing insights into effective approaches, this article aims to shed light on the ...
10 months ago Securityzap.com
Navigating Cybersecurity Budget Constraints for K-12 Schools - More than 647, 000 US students were impacted by hacks or attacks on their schools in 2021 alone, according to GAO.gov. Attacks against schools are increasing by 30% quarter-to-quarter. School districts may not seem like lucrative targets, especially ...
9 months ago Securityboulevard.com
Cybersecurity for Art and Design Schools - In the digital age, art and design schools face unique cybersecurity challenges. This article aims to shed light on the importance of cybersecurity in art and design schools and provide insights into safeguarding digital portfolios and ensuring ...
10 months ago Securityzap.com
Data Breaches in US Schools Exposed 37.6M Records - Since 2005, educational institutions in the United States have experienced 3713 data breaches, impacting over 37.6m records. According to new data by Comparitech, 2023 marked a record year, with 954 breaches recorded - a dramatic rise from 139 in ...
6 months ago Infosecurity-magazine.com
Developing Cybersecurity Awareness Programs for Schools - Schools are increasingly becoming targets for cyberattacks, necessitating the development of robust cybersecurity awareness programs. Ultimately, a comprehensive cybersecurity awareness program is essential for schools to mitigate risks, enhance ...
10 months ago Securityzap.com
How to perform a proof of concept for automated discovery using Amazon Macie | AWS Security Blog - After reviewing the managed data identifiers provided by Macie and creating the custom data identifiers needed for your POC, it’s time to stage data sets that will help demonstrate the capabilities of these identifiers and better understand how ...
1 month ago Aws.amazon.com
K-12 schools in Tucson, Nantucket respond to cyberattacks - Schools in Tucson, Arizona, and Nantucket, Massachusetts, are dealing with cyberattacks as U.S. schools continue to face a barrage of threats in the first weeks of 2023. A spokesperson from Tucson Unified School District told The Record that they ...
1 year ago Therecord.media
Cybersecurity Curriculum Development Tips for Schools - With the constant threat of cyber attacks, schools must prioritize the development of a robust cybersecurity curriculum to equip students with the necessary skills and knowledge. This article provides valuable insights and tips for schools aiming to ...
10 months ago Securityzap.com
Electronic Frontier Foundation - We're not just talking about the ballot box, but the everyday power we all have to demand government agencies make their records and data available to public scrutiny. At every level of government in the United States, there are laws that empower the ...
8 months ago Eff.org
Building a Culture of Digital Responsibility in Schools - In today's technologically-driven world, schools have a critical role in cultivating a culture of digital responsibility among students. Promoting digital responsibility involves educating students about the potential risks and consequences ...
10 months ago Securityzap.com
Critical insights into Australia's supply chain risk landscape - Australian organizations find themselves navigating a minefield of supply chain risks, with a surge in incidents stemming from multi-party breaches. These breaches are often caused by vulnerabilities in cloud or software providers and are emerging as ...
8 months ago Tripwire.com
US School Shooter Emergency Plans Exposed in a Highly Sensitive Database Leak - Every year, hundreds of millions of files, personal records, and documents are accidentally exposed online. Owners of dating apps, colossal marketing databases, and even a spy agency have published information to the web by leaving it in unsecured ...
10 months ago Wired.com
Apple: 2.5B Records Exposed, Marking Staggering Surge in Data Breaches - An Apple-commissioned report this week has highlighted once again why analysts have long recommended the use of end-to-end encryption to protect sensitive data against theft and misuse. The report is based on an independent study of publicly reported ...
11 months ago Darkreading.com
The Importance of Cybersecurity Education in Schools - Cybersecurity education equips students with the knowledge and skills needed to protect themselves and others from cyber threats. Cybersecurity education can teach students about the impact of cyberbullying, how to prevent it, and how to respond ...
11 months ago Securityzap.com
Classes cancelled as 'sinister' school cyber-attacks rise - BBC. Cancelled lessons and snaking lunchtime queues are among the ways pupils are being affected by an increasing number of cyber attacks on schools. New figures from the Information Commissioner's Office show 347 cyber incidents were reported in the ...
6 months ago Bbc.com
FCC proposes 3-year cybersecurity pilot for schools, libraries - Dive Brief: The Federal Communications Commission this week proposed a three-year pilot program to study how the agency's Universal Service Fund can help schools and libraries fight cybersecurity threats. The pilot program, which would cost up to ...
11 months ago Cybersecuritydive.com
New FCC Pilot Shores Up Security for K-12, Libraries - One month after the Seattle Public Library's systems went down as part of a ransomware attack, the library is just beginning to restore services to staff and patrons. Some resources are back and running, but the library is far from being fully ...
4 months ago Darkreading.com
Latest Information Security and Hacking Incidents - The confidential documents stolen from schools and dumped online by ransomware gangs are raw, intimate and graphic. They describe student sexual assaults, psychiatric hospitalizations, abusive parents, truancy - even suicide attempts. Cybercriminals ...
10 months ago Cysecurity.news
Tech Security Year in Review - In this Tech Security Year in Review for 2023, let's look into the top data breaches of the past year. Each factor contributes to the growing threatscape, demanding a proactive and adaptable cybersecurity approach to safeguard your organization ...
10 months ago Securityboulevard.com
West Virginia students returning to class after days-long outage following cyberattack - Nearly 20,000 students in West Virginia were forced to miss classes on Monday due to a cyberattack that crippled their school. Berkeley County Schools said on Friday it was experiencing an internet and phone outage on Friday and spent the weekend ...
1 year ago Therecord.media
Data theft plaguing K-12 schools after holiday season attacks - Schools across the U.S. remain fertile targets for hackers, with a slate of K-12 entities contending with cyberattacks and data thefts following the holiday season. Since the start of the year, a handful of schools have reported data breaches ...
9 months ago Therecord.media
Multiple colleges, K-12 schools facing outages after cyberattacks - Several K-12 schools, colleges and universities are dealing with significant technology outages due to cyberattacks this week. A spokesperson for North Carolina Central University told Recorded Future News that the school was alerted to a cyberattack ...
11 months ago Therecord.media
Apple-backed data breach report says 2.6 billion records leaked in 2 years - An Apple-commissioned data breach report found 2.6 billion records were stolen by hackers between 2021 and 2022. The report by MIT Professor of Information Technology Stuart Madnick, published Thursday, said breaches were up by 20% in the first three ...
11 months ago Scmagazine.com
Data Loss Prevention for Business: Strategies and Tools - Data Loss Prevention has become crucial in today's data-driven business landscape to protect sensitive information. This discussion aims to provide valuable insights into DLP strategies and tools for business, helping mitigate data loss risks ...
9 months ago Securityzap.com
Data Protection in Educational Institutions - This article delves into the significance of data protection in educational institutions, emphasizing three key areas: the types of educational data, data privacy regulations, and data protection measures. Lastly, robust data protection measures are ...
10 months ago Securityzap.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)