Hackers claim to steal 110,000 SSNs from Tenn. school system

Close to 9,000 SSNs belonging to students, employees publicly posted

A hitherto unknown hacking group claimed responsibility for a hacking attack on a county school system in Tennessee that may have exposed the names, Social Security numbers and other personal data belonging to about 110,000 people.

The group, which called itself Spex Security, later posted 14,500 of the compromised records online and has threatened to post more. Those affected by the breach include an unknown number of former and current students and employees of the Clarksville-Montgomery County School System (CMCSS).

In a message on Pastebin.com, an individual who appeared to be a member of the group suggested that the intrusion at CMCSS was carried out as retaliation for its "belligerence."

"To be clear here, we gave Tennessee a chance to comply and they didn't, therefore, this is the consequence they'll have to swallow," the rambling message stated.

"Our primary suspects include the U.S Government for torturous and deceptive acts on our own soil, the Educational system for exuberantly being blown over and belligerently not patching the holes in their system, and anybody else who partook a role in the Murder of America," the message said.

Elise Shelton, a CMCSS spokeswoman, said school system officials learned of the breach from the Clarksville Police Department, which received a tip from a caller.

The school system was able to confirm the breach on Monday and immediately took the site offline, she said. As of Wednesday afternoon, the main CMCSS.net site was still down, and there was no indication of when it will be restored, she said.

Investigators are still trying to determine what happened and it is not yet clear when the breach might have occurred or how it was done, Shelton said. It is also not immediately clear whether all the records that the hackers claimed to have accessed came from CMCSS, she said.

For the moment, the school system is assuming that records on an unknown number of its former and current employees and students have been breached. CMCSS has contacted all 4,000 or so of its current employees and roughly 31,400 enrolled students about the potential breach of their Social Security numbers and other personal data.

The real challenge is in notifying former employees and students, Shelton said. CMCSS is actively engaged with local news media to try and get the word out. About 8,000 of the affected students are "military-dependent" children from the U.S. Army's Fort Campbell, located on the state line between Tennessee and Kentucky. CMCSS authorities are working with the military to find a way to communicate details about the breach to military families whose children may have been affected, she said.

"We are working as quickly and as carefully as we can," to restore the school system's Web presence and to contact all those potentially affected by the breach, she said.

Meanwhile, Identity Finder, a New York-based company that provides software for redacting, deleting or otherwise protecting Social Security numbers and other sensitive data from laptops and desktop computers, said Tuesday that it has discovered close to 9,000 unique Social Security numbers related to the breach.

Of those, 4,942 numbers appear to belong to school district employees and 3,977 are those of students, the company's chief privacy officer Aaron Titus said Wednesday. In all cases, the full names and student IDs or employee IDs of those affected were also released. About 1,300 of the records also contained the gender and dates of birth of the students. The files containing the information appear to have been taken offline by authorities, he said.

According to Titus, Identity Finder has been keeping an eye out for the information since June 6, when a hacker the company monitors tweeted about plans to release more than 100,000 state records. The hacker later posted redacted images of files obtained from CMCSS but initially vowed not to publicly release the information.

That changed in less than 24 hours, and the information was publicly released, Titus said. Titus said he contacted Clarksville police on Sunday after discovering the information posted online.

"Clarksville's response is to be commended," Titus said. "They were very responsive and took every reasonable precaution once they knew they had a problem," he said. It's unclear if the hackers plan to release any more of the information they claim to have purloined, he added.

A Twitter account that appeared to belong to Spex Security seemed to reflect some uncertainty on the part of the hackers after the incident. Three hackers who appeared to have been behind the intrusion and release of information at CMCSS claimed they were retiring from black hat hacking and had become white hat hackers instead.

"We are gone! Tada," one tweet proclaimed, only to be followed by another one a few hours ago, announcing, "We're back."

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com.

See more by Jaikumar Vijayan on Computerworld.com.

Join the discussion
Be the first to comment on this article. Our Commenting Policies