Nelnet Servicing in Nebraska provides technology services to EdFinancial and OSLA identified a vulnerability in its systems that resulted in a data breach incident.
Certain student loan account registration information including name, address, email address, phone number, and Social Security number was accessible by an unknown party beginning in June 2022 and ending on July 22, 2022.
Nelnet Servicing’s cybersecurity team took immediate action to secure the information system, block the suspicious activity, fix the issue and launched an investigation with third-party forensic experts to determine the nature and scope of the activity.
However, the investigation revealed that a total of 2,501,324 people were affected by this incident.
TPRM report: https://scoringcyber.rankiteo.com/company/nelnet
"id": "nel21681122",
"linkid": "nelnet",
"type": "Vulnerability",
"date": "08/2022",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of a geographical region"
{'affected_entities': [{'customers_affected': 2501324,
'industry': 'Education Finance',
'location': 'Nebraska',
'name': 'Nelnet Servicing',
'type': 'Technology Services Provider'}],
'attack_vector': 'System Vulnerability',
'data_breach': {'number_of_records_exposed': 2501324,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information']},
'date_detected': '2022-07-22',
'description': 'Nelnet Servicing identified a vulnerability in its systems '
'resulting in a data breach where student loan account '
'registration information was accessible by an unknown party '
'from June 2022 to July 22, 2022.',
'impact': {'data_compromised': ['Name',
'Address',
'Email Address',
'Phone Number',
'Social Security Number']},
'investigation_status': 'Completed',
'response': {'containment_measures': 'Secured the information system, blocked '
'suspicious activity',
'incident_response_plan_activated': True,
'remediation_measures': 'Fixed the issue',
'third_party_assistance': True},
'threat_actor': 'Unknown',
'title': 'Nelnet Servicing Data Breach',
'type': 'Data Breach'}