Rensselaer Polytechnic Institute

Rensselaer Polytechnic Institute

The Rensselaer Polytechnic Institute (RPI) experienced a data breach in its Athletic Trainer System (ATS), discovered and reported on February 1, 2024, though the incident occurred between January 2020 and January 2021. The breach exposed sensitive personal information of students, including names, dates of birth, injury details, and potentially Social Security numbers. The exact number of affected individuals remains undisclosed. The FBI is actively prosecuting the party responsible for the breach. The compromised data particularly Social Security numbers poses significant risks, including identity theft, financial fraud, and long-term reputational harm to the institution. While the breach did not involve ransomware or immediate operational disruptions, the exposure of highly sensitive student records elevates the severity due to the potential for misuse of personal and financial data. The delayed discovery (2020–2021 to 2024) further exacerbates concerns about prolonged vulnerability and regulatory scrutiny under data protection laws.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d73d16d9-7706-42aa-b43d-0c96daccc02f.shtml

TPRM report: https://www.rankiteo.com/company/rensselaer-hartford-campus

"id": "ren226082125",
"linkid": "rensselaer-hartford-campus",
"type": "Breach",
"date": "1/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unspecified number of students',
                        'industry': 'Higher Education',
                        'location': 'Troy, New York, USA',
                        'name': 'Rensselaer Polytechnic Institute (RPI)',
                        'type': 'Educational Institution'}],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal Identifiable '
                                              'Information (PII)',
                                              'Protected Health Information '
                                              '(PHI)']},
 'date_detected': '2024-02-01',
 'date_publicly_disclosed': '2024-02-01',
 'description': 'The Rensselaer Polytechnic Institute (RPI) reported a data '
                'breach involving the Athletic Trainer System (ATS), '
                'compromising personal information of students, including '
                'names, dates of birth, injury details, and potentially social '
                'security numbers. The breach occurred between January 2020 '
                'and January 2021, with the FBI prosecuting the responsible '
                'party.',
 'impact': {'data_compromised': ['names',
                                 'dates of birth',
                                 'injury details',
                                 'potentially social security numbers'],
            'identity_theft_risk': 'High (PII and potentially SSNs exposed)',
            'systems_affected': ['Athletic Trainer System (ATS)']},
 'investigation_status': 'Ongoing (FBI prosecution in progress)',
 'regulatory_compliance': {'legal_actions': ['FBI prosecution of responsible '
                                             'party']},
 'response': {'law_enforcement_notified': True,
              'third_party_assistance': ['FBI (prosecuting the responsible '
                                         'party)']},
 'title': 'Rensselaer Polytechnic Institute (RPI) Athletic Trainer System '
          '(ATS) Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.