Active Network reports severe breach of school management software


By MYBRANDBOOK


Active Network reports severe breach of school management software

Early this week, a severe security breach has been disclosed by a web-based school accounting software company, Active Network. Based out of US, it provides software for K-12 schools and districts.  

 

The company said that the hackers got access to the software platform named Blue Bear which facilitates administration and management of school accounting, student fees, and online stores on behalf of schools and other educational institutions.

 

As per Active Network, parents who accessed a school's (Blue Bear-based) web store to pay school fees or buy books and school supplies between October 1, 2019, and November 13, 2019, might have had their personal data stolen by hackers.

 

The hackers may stole data like name, payment card number, payment card expiration date, payment card security code, and store username and password.

 

The school is investigating on the incident and has notified the affected parents.  

 

Based on the type of data Active Network said hackers might have collected, this appears to be a so-called web skimming (Magecart) attack -- where hackers breached Active Network's Blue Bear platform and planted malicious code on Blue Bear school stores that collected users' payment details in real-time, while they were paying fees and products.

 

These types of attacks were some of the most common hacks last year, and the FBI issued a security alert last October, warning the US private sector to deploy security measures and safeguard online stores against possible compromises.

 

A Tulsa-based law firm is currently conducting an investigation into the breach, and asking impacted victims to come forward, in the hopes of filing a class-action lawsuit.

 

 E-Magazine 
 VIDEOS  Placeholder image

Copyright www.mybrandbook.co.in @1999-2024 - All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.
Other Initiatives : www.varindia.com | www.spoindia.org