WHID 2008-28: Confidential data on thousands of students exposed by test preparatory firm

Attack Information
WHID ID: 
2008-28
Date Occured: 
20 Sep 2008
Attack Method: 
Outcome Information
Target Information
Attacked Entity Field: 
Education
Attacked Entity Geography: 
USA

While moving to a new hosting provider, a system by Princeton Review used by student to prepare for a state assessment program exposed due to misconfiguration approximately 34,000 students from 2nd to 10th grade. The information included names, Florida ID (which is nearly identical to the US social security number) and the students exam report.

The information was available for available online from late June to early August.

Additional information: