News: 1686072850

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Identity thieves can hunt us for 'rest of our lives,' claims suit after university data leak

(2023/06/06)


An American university founded in 1833 is facing a bunch of class action lawsuits after the personal data of nearly 100,000 people was stolen from its tech infrastructure.

And because the data includes the identity fraud goldmine of the victims' names and social security numbers (SSNs), one of the lawsuits claims the danger to those affected could continue throughout "their lives."

[1]SSNs are assigned at birth, and never change, and they allow US government agencies to identify individuals in their records and "businesses to track an individual's financial information." With just an SSN, name, and address, criminals can take out a credit card or loan in the victim's name. It can also be used to obtain medical care (and rack up bills) in the person's name, or the criminal can identify themselves using it when arrested - giving the victim a [2]criminal record .

[3]

Attackers spent 12 days rummaging through servers and posted the personal details they found on the dark web. According to the data breach notice by Mercer University in Macon, Georgia, 93,512 people were affected.

[4]

[5]

One of the complaints alleges the attackers were members of the Akira ransomware gang, which, according to [6]Sophos , uses a "retro aesthetic on their victim site" reminiscent of green screen consoles and was possibly named for the [7]1988 anime film .

The complaints – all of which ask for a jury trial – include one from visiting Yale professor Jennifer Kilkus

[8]PDF

, who taught at Mercer uni from 2016 to 2018; another from an unnamed alumnus calling themselves John Doe

[9]PDF

, who says he suffered fraudulent credit card charges after the breach; and another from former student Ping Wang

[10]PDF

.

[11]

The breach notice said the attack took place over February 12-24 and was only discovered on April 30. Data including name and "other personal identifiers" in combination with driver's licenses and Social Security numbers (SSNs) was nicked. Kilkus, however, says in her complaint that "if Mercer had exercised reasonable diligence in its investigation, it would have learned far sooner" that the personally identifiable information (PII) had been exposed."

All of the lawsuits allege negligence, claiming little care was taken to protect the plaintiffs' PII, with Doe's suit alleging: "Not until over a month after it claims to have discovered the data breach did defendant begin sending the notice to persons whose PII and/or financial information defendant confirmed was potentially compromised as a result of the data breach."

Wang's lawsuit, meanwhile, specifically calls out the uni for allegedly not putting into place basic network segmentation or encrypting the confidential information that was leaked.

[12]

The complaint states: "Mercer University had far too much confidential unencrypted information held on its systems."

Mercer released a [13]statement on May 9 saying: "Although the University has taken extensive measures to protect the privacy of its information, some data – Social Security numbers and driver's license numbers – were removed from its systems without authorization. The University has found no evidence that personal financial information was removed."

[14]US veterans' data exposed after burglary

[15]Criminals spent 10 days in US dental insurer's systems extracting data of 9 million

[16]T-Mobile US suffers second data theft within months

[17]Data loss costs are going up – and not just for those who choose to pay thieves

The Register noticed Mercer filed the data breach notice with the Maine state attorney general, under a law which only applies to personal data that is not encrypted, but not wanting to take this at face value, we asked the institution whether it had any encryption in place. It declined to comment on pending litigation.

Wang's complaint also alleges that "according to postings on the dark web" where the Akira gang allegedly posted the defendants' private information, the miscreants "stated that Mercer University had refused to pay the ransom."

The breach notice filed with the Maine attorney general included the sample letter sent to those affected, which stated: "Mercer University takes the security of our computer systems very seriously. Even so, like many higher education institutions, we recently experienced unlawful access into our computer systems." It said it offered "complimentary identity theft protection services through a one-year membership with Experian IdentityWorks."

It's debatable whether one year will be enough. Wang's complaint claims: "For the rest of their lives, plaintiff and the class members will have to deal with the danger of identity thieves possessing and misusing their private information."

Kilkus's complaint alleges the university failed to train staffers on basic infosec protocols, and that given the type of data Mercer collected and stored, "it was highly foreseeable that bad actors would attempt to access it without permission."

The Federal government [18]advises that "each time an individual divulges his or her SSN" there is "potential for a thief to illegitimately gain access to bank accounts, credit cards, driving records, tax and employment histories and other private information increases."

It [19]recommends that SSNs should only be collected as a last resort, and that they must be stored in an encrypted fashion.

The Feds learned the hard way, only requiring encryption of sensitive data stored on its laptops after a 2006 theft of computer equipment that contained data on [20]26.5 million veterans . ®

Get our [21]Tech Resources



[1] https://www.ssa.gov/policy/docs/ssb/v69n2/v69n2p55.html

[2] https://www.lexingtonlaw.com/blog/negative-items/4-things-identity-thieves-can-do-with-your-social-security-number.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZH@sgntXp22tXMafa2mMkAAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZH@sgntXp22tXMafa2mMkAAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZH@sgntXp22tXMafa2mMkAAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/

[7] https://www.youtube.com/watch?v=nA8KmHC2Z-g&ab_channel=RetroBiografen

[8] https://regmedia.co.uk/2023/06/06/kilkus_v_mercer.pdf

[9] https://regmedia.co.uk/2023/06/06/doe_v_mercer.pdf

[10] https://regmedia.co.uk/2023/06/06/wang_v_mercer.pdf

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZH@sgntXp22tXMafa2mMkAAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZH@sgntXp22tXMafa2mMkAAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://den.mercer.edu/mercer-university-statement-on-data-incident

[14] https://www.theregister.com/2006/05/23/va_data_security_breach/

[15] https://www.theregister.com/2023/05/31/mcna_breach/

[16] https://www.theregister.com/2023/05/08/in_brief_security/

[17] https://www.theregister.com/2023/05/02/data_breach_costs_rise/

[18] https://www.ssa.gov/phila/ProtectingSSNs.htm#:~:text=Organizations%20that%20maintain%20SSNs%20in,to%20have%20access%20to%20it.

[19] https://www.ssa.gov/phila/ProtectingSSNs.htm

[20] https://www.theregister.com/2006/05/23/va_data_security_breach/

[21] https://whitepapers.theregister.com/



Doctor Syntax

"SSNs are assigned at birth, and never change"

Given the extent to which these have been plundered (and equivalent identifiers in other jurisdictions) maybe it's a principle that needs to be rethought.

"SSNs are assigned at birth, and never change"

Anonymous Coward

I notice that swerves the question of whether they are unique or not.

UK readers should be well aware that National Insurance Numbers are not. No idea if that is by design, or oversight. But it's one to bear in mind.

Mind you, who needs identity theft to mess your life up ?

https://www.independent.co.uk/travel/news-and-advice/man-banned-easyjet-flights-name-b2352121.html

Re: "SSNs are assigned at birth, and never change"

elDog

SSNs are not unique. They need to be re-used given the small range of possibilities.

9 digits, some of which are pre-allocated and possibly known by other means.

If there is a common hashing or encryption algorithm, easily deduced from the product of that algorithm.

Re: "SSNs are assigned at birth, and never change"

doublelayer

Wikipedia indicates this to be incorrect:

The Social Security Administration does not reuse Social Security numbers. It has issued over 450 million since the start of the program, about 5.5 million per year. It says it has enough to last several generations without reuse and without changing the number of digits.[41] There have been accidental assignments of the same number to more than one person.[42]

In addition, it appears that numbers beginning with the digit 9 are not permitted, so that would allow for expansion if the key space is exhausted without breaking old numbers.

Re: "SSNs are assigned at birth, and never change"

chivo243

Yes, the same number has been assigned to two people with the same name who emigrated from Korea if I'm not mistaken...

and my memory still works... https://nextshark.com/ssa-korean-immigrants-same-social-security-number

And as far using the SSN as a personal identifier, it was never meant to be. It's been abused like the redheaded step child since I first started working in 1978. It was my employee number at many places. It was supposed to only be used for the SSAdministration, or so I was informed many decades ago.

Re: "SSNs are assigned at birth, and never change"

Claptrap314

Okay, I'll show my age: That was explicitly stated on my SS card when I received it. I was twelve (grew up on a farm). I did not trust it then....

Re: "SSNs are assigned at birth, and never change"

doublelayer

This appears to fall into the "accidental assignments of the same number to more than one person" category as quoted. They're supposed to be unique, but it's a government system and sometimes they fail. I'm not trying to pretend that they do anything well, from assignment to use, but that doesn't change the fact that reuse of the numbers is not part of the planned system, and when it appears, it's an error which must be corrected.

OK, I'll bite

Anonymous Coward

"The Register noticed Mercer filed the data breach notice with the Maine state attorney general, under a law which only applies to personal data that is not encrypted, but not wanting to take this at face value, we asked the institution whether it had any encryption in place. It declined to comment on pending litigation."

Why would a University in Macon, Georgia, file a data breach notice with the Maine State Attorney General, a State 1200 miles away?

Re: OK, I'll bite

RM Myers

Mercer filed the breach letter with a number of different states (probably every state that has a legal requirement), since they would have alumni living in every state. Maine nicely posted the information on their website, and since they only require the data breach notice IF there is unencrypted data, the author was able to infer that some data was unencrypted.

This does need to be taken much more seriously.

elDog

A lifetime ruined and a crappy credit score as a reward.

First of all, the credit scoring agencies are just as suspect for leaking personal information as many of the merchants.

But the company that accepts personally identifiable information (or other variations) should be held accountable for all the damage that can occur if that is used for nefarious purposes.

While this particular article is about exfiltrating this information, there are lots of situations where the companies in question also mis-use the information and cause harm (sharing with "trusted" partners).

I suggest a surety bond for every customer be placed in a trusted place (not sure what that is anymore) and any negative actions and pain-and-suffering penalties be paid from that accumulated bond. Probably $100,000 per customer? Also the officers and directors of said companies be held personally responsible for payments that exceed the bond amount.

With just an SSN,

Yet Another Anonymous coward

So stop using Social Security Numbers as if they were some magic secret key.

They are just to (hopefully) unambiguously name somebody - knowing the number doesn't prove you are that person !

Re: With just an SSN,

Tomato42

That's how personal ID numbers work in civilised countries. But the Anglophone countries can't have ID cards, so you get the worst of both worlds. Bravo!

Re: With just an SSN,

Doctor Syntax

"so you get the worst of both worlds"

Which are the two worlds you're referring to? As a native of an Anglophone country I'd rate abuse of ID cards by TPTB to be one those of which you can have the worst.

Consequences

Dropper

I've always thought that the only consequence that would truly force businesses to take security seriously, and enforce the use of encryption as well as the decision to not store information for the sake of it, is to make them 100% liable for the financial damage done to every individual who suffers from a breach.

If they had to make payments to refund victims for the cost of making purchases at high interest rates (due to the resulting bad credit score), that would be step in the right direction.

Another would be to force them to finance the purchase of cars and homes at the perfect credit score rates.

Not practical? Nor is having to pay 20-30% more for major purchases for years because someone at a company the victim did business with thought it was too expensive to implement proper security.

Nice guys don't finish nice.