A criminal phishing fraud that hijacked two email accounts in the registrar's office led to the notification of Clarion University of an email compromise.
The accounts were accessed by the unauthorised person or persons between October 7 and October 10.
Data integrity and privacy protection are important to Clarion University, according to Tina Horner, communication manager.
The email hack may have disclosed 408 pupils' Social Security and/or driver's licence information.
Source: https://www.databreaches.net/clarion-u-students-notified-after-employees-fall-for-phishing-attack/
TPRM report: https://scoringcyber.rankiteo.com/company/clarioneducation
"id": "cla16214323",
"linkid": "clarioneducation",
"type": "Breach",
"date": "12/2017",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 408,
'industry': 'Education',
'name': 'Clarion University',
'type': 'Educational Institution'}],
'attack_vector': 'Email Phishing',
'data_breach': {'number_of_records_exposed': 408,
'personally_identifiable_information': ['Social Security '
'numbers',
"Driver's license "
'information'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Social Security numbers',
"Driver's license information"]},
'description': 'A criminal phishing fraud that hijacked two email accounts in '
"the registrar's office led to the notification of Clarion "
'University of an email compromise. The accounts were accessed '
'by the unauthorised person or persons between October 7 and '
'October 10. Data integrity and privacy protection are '
'important to Clarion University, according to Tina Horner, '
'communication manager. The email hack may have disclosed 408 '
"pupils' Social Security and/or driver's licence information.",
'impact': {'data_compromised': ['Social Security numbers',
"Driver's license information"]},
'initial_access_broker': {'entry_point': 'Email Phishing'},
'title': 'Phishing Fraud Compromises Email Accounts at Clarion University',
'type': 'Phishing Fraud'}