Hacker Steals Ten Years Worth of Data From San Diego School District (zdnet.com)
A hacker has stolen the personal details of over 500,000 San Diego Unified School District staff and students, the district revealed in a breach notice posted on its website Friday. From a report: The breach occurred because the attacker gained access to staff credentials via a tactic known as phishing -- sending authentic-looking emails that redirect users to fake login pages were attackers collect login credentials. The attack didn't go unnoticed. Some staff reported the funny-looking emails to IT staff, who investigated and eventually discovered the breach in October this year. District officials said the hacker had access to its network between January 2018 and November 1, 2018, but that he stole student and staff data going back to the 2008-2009 school year.
I was informed by a security expert at a technology convention that personal data (Name, BD, SSN) of children are some of the most valuable data sought after on the dark web. When adults have their security credentials stolen, they discover the theft rather quickly, and any accounts created with the stolen data are shut down in a matter of weeks, giving the stolen credentials little potential value. But children do not check bank account information, or credit card balances, or credit scores until they become adults. Hackers can use that information to bankroll illegal financial activity for years.
Someone enrolled now in preschool may discover 15 years later when they fill out their FAFSA that they owe hundreds of thousands of dollars in unpaid credit card balances and financial loans. San Diego School District will be liable for decades to come.