Emerson College

Emerson College

Emerson College suffered a data breach caused by the inadvertent disclosure of sensitive information by a third-party vendor. The incident, which occurred between August 23, 2021, and May 8, 2022, exposed the names and driver’s license numbers of 816 individuals, including five Maine residents who were formally notified on September 19, 2022. While the breach did not involve financial data or large-scale identity theft, the exposure of government-issued identification (driver’s license numbers) poses a risk of fraud or misuse. In response, Emerson College is providing 12 months of credit monitoring via Experian to affected individuals as a mitigating measure. The breach highlights vulnerabilities in third-party vendor security practices, emphasizing the need for stricter oversight in handling personally identifiable information (PII).

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e533fbae-5876-42ce-a6a5-bc289b53f1e0.shtml

TPRM report: https://www.rankiteo.com/company/emerson-college-graduate-programs

"id": "eme135082125",
"linkid": "emerson-college-graduate-programs",
"type": "Breach",
"date": "8/2021",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 816,
                        'industry': 'Higher Education',
                        'location': 'Boston, Massachusetts, USA',
                        'name': 'Emerson College',
                        'type': 'Educational Institution'},
                       {'name': 'Unnamed Third-Party Vendor',
                        'type': 'Vendor/Service Provider'}],
 'attack_vector': 'Inadvertent Disclosure by Third-Party Vendor',
 'customer_advisories': ['Written notifications sent to affected individuals '
                         '(including 5 Maine residents)'],
 'data_breach': {'data_exfiltration': 'Yes (unauthorized access)',
                 'number_of_records_exposed': 816,
                 'personally_identifiable_information': ['Names',
                                                         "Driver's License "
                                                         'Numbers'],
                 'sensitivity_of_data': "High (includes driver's license "
                                        'numbers)',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)']},
 'date_publicly_disclosed': '2022-09-19',
 'description': 'The Maine Office of the Attorney General reported that '
                'Emerson College experienced a data breach due to inadvertent '
                'disclosure by a third-party vendor, affecting 816 '
                'individuals. The breach involved unauthorized access to names '
                "and driver's license numbers. Emerson College is offering 12 "
                'months of credit monitoring through Experian to those '
                'potentially affected.',
 'impact': {'brand_reputation_impact': 'Potential reputational harm due to '
                                       'exposure of sensitive personal data',
            'data_compromised': ['Names', "Driver's License Numbers"],
            'identity_theft_risk': "High (due to exposure of driver's license "
                                   'numbers)'},
 'investigation_status': 'Disclosed; remediation ongoing (credit monitoring '
                         'offered)',
 'post_incident_analysis': {'root_causes': 'Inadvertent disclosure by a '
                                           'third-party vendor'},
 'references': [{'source': 'Maine Office of the Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': ['Maine Office of the '
                                                        'Attorney General']},
 'response': {'communication_strategy': ['Written notification to affected '
                                         'individuals (including 5 Maine '
                                         'residents)'],
              'incident_response_plan_activated': 'Likely (given notification '
                                                  'and remediation steps)',
              'remediation_measures': ['Offering 12 months of credit '
                                       'monitoring to affected individuals'],
              'third_party_assistance': ['Experian (credit monitoring '
                                         'services)']},
 'title': 'Emerson College Data Breach via Third-Party Vendor',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.