The School Town of Munster experienced a data security incident after a student gained access to an administrative file back and copied private information.
The officials noticed the incident on Oct. 26 after they noticed an administrative file in an unexpected location.
Through an investigation, they found that a student gained access to copy the administrative file from a food services system.
The administrative file included student names, Social Security numbers, birth data, student identification, address and parents’ names and email addresses.
TPRM report: https://scoringcyber.rankiteo.com/company/school-town-of-munster
"id": "sch2154141222",
"linkid": "school-town-of-munster",
"type": "Data Leak",
"date": "04/2022",
"severity": "50",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Education',
'location': 'Munster',
'name': 'School Town of Munster',
'type': 'Educational Institution'}],
'attack_vector': 'Unauthorized Access',
'data_breach': {'data_exfiltration': True,
'file_types_exposed': ['Administrative file'],
'personally_identifiable_information': ['Student names',
'Social Security '
'numbers',
'Birth data',
'Student '
'identification',
'Address',
'Parents’ names and '
'email addresses'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information']},
'date_detected': '2023-10-26',
'description': 'The School Town of Munster experienced a data security '
'incident after a student gained access to an administrative '
'file back and copied private information.',
'impact': {'data_compromised': ['Student names',
'Social Security numbers',
'Birth data',
'Student identification',
'Address',
'Parents’ names and email addresses'],
'systems_affected': ['Food services system']},
'initial_access_broker': {'entry_point': 'Food services system'},
'motivation': 'Unknown',
'references': [{'source': 'Cyber Incident Description'}],
'threat_actor': 'Student',
'title': 'Data Security Incident at School Town of Munster',
'type': 'Data Breach',
'vulnerability_exploited': 'Weak Access Controls'}