An online loophole in the network of the University of Otago allowed a handful of users to access a veritable treasure trove of information.
The types of information exposed in the in included phone numbers, addresses, passport details, exam results, police vetting lists, academic integrity investigation invitation letters, referee reports, passport scans, p-card receipts, and invoices.
however, the university was alerted to the loophole and soon it closed it.
TPRM report: https://scoringcyber.rankiteo.com/company/university-of-otago
"id": "uni0221222",
"linkid": "university-of-otago",
"type": "Breach",
"date": "12/2022",
"severity": "80",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Education',
'name': 'University of Otago',
'type': 'Educational Institution'}],
'attack_vector': 'Online Loophole',
'data_breach': {'type_of_data_compromised': ['phone numbers',
'addresses',
'passport details',
'exam results',
'police vetting lists',
'academic integrity '
'investigation invitation '
'letters',
'referee reports',
'passport scans',
'p-card receipts',
'invoices']},
'description': 'An online loophole in the network of the University of Otago '
'allowed a handful of users to access a veritable treasure '
'trove of information. The types of information exposed '
'included phone numbers, addresses, passport details, exam '
'results, police vetting lists, academic integrity '
'investigation invitation letters, referee reports, passport '
'scans, p-card receipts, and invoices. However, the university '
'was alerted to the loophole and soon closed it.',
'impact': {'data_compromised': ['phone numbers',
'addresses',
'passport details',
'exam results',
'police vetting lists',
'academic integrity investigation invitation '
'letters',
'referee reports',
'passport scans',
'p-card receipts',
'invoices']},
'title': 'Data Breach at University of Otago',
'type': 'Data Breach',
'vulnerability_exploited': 'Network Vulnerability'}