Hackers claim to steal 110,000 SSNs from Tenn. school system
Close to 9,000 SSNs belonging to students, employees publicly posted
Computerworld - A hitherto unknown hacking group claimed responsibility for a hacking attack on a county school system in Tennessee that may have exposed the names, Social Security numbers and other personal data belonging to about 110,000 people.
The group, which called itself Spex Security, later posted 14,500 of the compromised records online and has threatened to post more. Those affected by the breach include an unknown number of former and current students and employees of the Clarksville-Montgomery County School System (CMCSS).
In a message on Pastebin.com, an individual who appeared to be a member of the group suggested that the intrusion at CMCSS was carried out as retaliation for its "belligerence."
"To be clear here, we gave Tennessee a chance to comply and they didn't, therefore, this is the consequence they'll have to swallow," the rambling message stated.
"Our primary suspects include the U.S Government for torturous and deceptive acts on our own soil, the Educational system for exuberantly being blown over and belligerently not patching the holes in their system, and anybody else who partook a role in the Murder of America," the message said.
Elise Shelton, a CMCSS spokeswoman, said school system officials learned of the breach from the Clarksville Police Department, which received a tip from a caller.
The school system was able to confirm the breach on Monday and immediately took the site offline, she said. As of Wednesday afternoon, the main CMCSS.net site was still down, and there was no indication of when it will be restored, she said.
Investigators are still trying to determine what happened and it is not yet clear when the breach might have occurred or how it was done, Shelton said. It is also not immediately clear whether all the records that the hackers claimed to have accessed came from CMCSS, she said.
For the moment, the school system is assuming that records on an unknown number of its former and current employees and students have been breached. CMCSS has contacted all 4,000 or so of its current employees and roughly 31,400 enrolled students about the potential breach of their Social Security numbers and other personal data.
The real challenge is in notifying former employees and students, Shelton said. CMCSS is actively engaged with local news media to try and get the word out. About 8,000 of the affected students are "military-dependent" children from the U.S. Army's Fort Campbell, located on the state line between Tennessee and Kentucky. CMCSS authorities are working with the military to find a way to communicate details about the breach to military families whose children may have been affected, she said.
- Path Selection Infographic Path Selection Infographic
- Hyperconvergence Infographic A wide range of observers agree that data centers are now entering an era of "hyperconvergence" that will raise network traffic levels faster...
- Preparing Your Infrastructure for the Hyperconvergence Era From cloud computing and virtualization to mobility and unified communications, an array of innovative technologies is transforming today's data centers.
- How WAN Optimization Helps Enterprises Reduce Costs If you wanted to break down innovation into a tidy equation, it might go something like this: Technology + Connectivity = Productivity. Productivity...
- Cloud Knowledge Vault Learn how your organization can benefit from the scalability, flexibility, and performance that the cloud offers through the short videos and other resources...
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users? All Cybercrime and Hacking White Papers | Webcasts