Brit unis hit in Blackbaud hack inform students that their data was nicked, which has gone as well as you might expect
- Reference: 1595598913
- News link: https://www.theregister.co.uk/2020/07/24/blackbaud_uk_universities_data_breaches/
- Source link:
As hack notifications started filtering through the world of student and alumni relations management software, news reports emerged this week of universities alerting people to a supply chain attack.
Uncommonly well-informed people [1]knew all about it by reading The Register 's report of the Blackbaud ransom payment last week, but mere Muggles only heard of it when universities began informing students, staff and alumni that their personal data had been nicked.
Cloud biz Blackbaud caved to ransomware gang's demands – then neglected to inform customers for two months [2]READ MORE
The BBC [3]put together a list of UK institutions subscribing to Blackbaud services. Of those, a dozen had been affected – including the Universities of York, Leeds, Manchester and Exeter among others – while five, including Queen's University Belfast and University College London, said they had not.
Blackbaud was struck by ransomware in May that locked up files on its "self-hosted" systems and not those running on AWS or Azure cloud environments. As the company admitted in a statement two months later: "Because protecting our customers' data is our top priority, we paid the cybercriminal's demand with confirmation that the copy they removed had been destroyed."
The University of Manchester sent its alumni an email, seen by The Register , which said in part:
Blackbaud has confirmed to us that:
it has conducted an investigation (involving law enforcement agencies);
no passwords, credit card details or bank account information were affected;
and it obtained confirmation that the data removed by the cybercriminal was destroyed;
it has no reason to believe that any data went beyond the cybercriminal, was or will be misused or will be disseminated or otherwise made available publicly.
The University of York told its students and alumni on Wednesday that names, dates of birth, student numbers, addresses, phone and email addresses, fundraising details (including details of donations), details of occupation and employer details were among the data stolen, according to [4]student news site York Mix .
Leeds University alumnus Chloe Roche [5]told the Yorkshire Post that her former institution had passed on the news that Blackbaud paid off the ransomware criminals in exchange for a promise that the crims would delete the stolen data.
She said: "We have been notified that Blackbaud have paid a ransom for the hackers to destroy our private information, but I find that really disconcerting too. Ultimately, we've no way of knowing what has actually been done with our data and the idea that a company is being blackmailed for it makes me feel really uneasy. The potential for it to be sold or passed on also worries me so it's very stressful."
Over on Twitter, Blackbaud's social media department failed to acknowledge the data breach. Its latest tweet at the time of writing was something about corporate social responsibility:
[6]
Our [7]#CSR leader, [8]@RachelHutchssn , recently took to the mainstage of [9]@socinnovation to share insights into the future of giving + philanthropy. Take a look: [10]https://t.co/3dsnerxNlo [11]pic.twitter.com/H43NlgL4Ga — Blackbaud (@blackbaud) [12]July 23, 2020
Supply chain attacks, where middlemen and processors of important data become targets rather than companies or institutions themselves, are lower-profile targets than they otherwise might be. Until, that is, something like this happens.
So far there is no information on how the criminals got into Blackbaud's network to spread their ransomware. Paying the ransom, however, merely encourages them and sustains the criminal business model. Don't do it – and don't trust assurances from criminals that they'll stick by their word. They're criminals, after all. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2020/07/17/blackbaud_paid_ransomware/
[2] https://www.theregister.com/2020/07/17/blackbaud_paid_ransomware/
[3] https://www.bbc.co.uk/news/technology-53516413
[4] https://www.yorkmix.com/university-of-york-hit-by-serious-data-breach-as-personal-details-of-staff-students-and-supporters-stolen/
[5] https://www.yorkshirepost.co.uk/education/university-leeds-second-yorkshire-confirm-blackbaud-ransomware-breach-2922396
[6] https://www.yorkshirepost.co.uk/education/university-leeds-second-yorkshire-confirm-blackbaud-ransomware-breach-2922396
[7] https://twitter.com/hashtag/CSR?src=hash&ref_src=twsrc%5Etfw
[8] https://twitter.com/RachelHutchssn?ref_src=twsrc%5Etfw
[9] https://twitter.com/socinnovation?ref_src=twsrc%5Etfw
[10] https://t.co/3dsnerxNlo
[11] https://t.co/H43NlgL4Ga
[12] https://twitter.com/blackbaud/status/1286361235076907019?ref_src=twsrc%5Etfw
[13] https://whitepapers.theregister.com/
At this point they know they are definitely dealing with a criminal who sees intrusion, theft, and blackmail as being legitimate means to acquire wealth. It rather begs the question of why lying about destruction an reselling the data would be seen as verbotten, doesn't it?
Ah, you've seen https://www.theregister.com/2020/07/23/carding_forum_scams/, I presume.
Of course, the storage was actually illegal
EU data cannot be stored in US servers. It's called GDPR.
https://noyb.eu/en/next-steps-users-faqs
Re: Of course, the storage was actually illegal
Nowhere in the story does it say that the data was stored in US servers. The hacked servers are described as "self-hosted," so if the servers were administered by the universities, the onus of GPDR compliance was on them.
Which doesn't make any of this look any better for Blackbaud, of course.
I see.
"...to share insights into the future of giving + philanthropy."
They certainly seem to have lived up to their aspirations on that score. What a pity that the recipients of their generosity happen to be a gang of criminals.
Just received the email
Just received the email from one of my alma maters. Assurance that no payment information was taken but warning to be aware of phishing as personal details taken. Not sure if I'll be able to spot any fallout of this from all the other phishing emails that turn up... Basically, we're all vulnerable and sufficient information about most of us is out there if anyone wants it; a database like this probably gets a premium so I, too, doubt it hasn't been deleted (after all, what do the crime have to lose)...
Re: Just received the email
Likewise, received email from a university where I have attended events in the past (public lectures) - not as an alumnus.
What was my data as an EU citizen (then - pre-Jan 2020) doing on servers in the US? Isn’t this proscribed under GDPR?
Re: Just received the email
Also been notified (am an alumni in my case).
Thankyou
My third has now been upgraded to a first.
"Because protecting our customers' data is our top priority, we paid the cybercriminal's demand with confirmation that the copy they removed had been destroyed."
Yeah, I'm sure they did.