National Student Clearinghouse MOVEit Breach
Mid 2023. The signature supply-chain breach of 2023. One file-transfer flaw cascaded across nearly 900 institutions, the textbook argument for tracking your vendors’ sub-processors.
What happened
The Clop gang exploited a zero-day in the MOVEit file-transfer tool to steal data from the National Student Clearinghouse, which handles enrollment and degree records for nearly every US institution. The flaw was not in the Clearinghouse itself; it was in a tool the Clearinghouse used. The breach was later settled for $9.95 million.
Confirmed exposed
- Names, dates of birth, contact information
- Social Security numbers and student ID numbers
- Enrollment, degree, and course-level records
Confirmed not exposed
- Exposure depended on which records each institution had submitted to the Clearinghouse
Nearly 900 colleges and universities were affected; the Clearinghouse notice also reached high schools and education organizations. The Maine AG filing named 51,000+ individuals.
Why it belongs in this library
One vendor's file-transfer flaw cascaded across hundreds of institutions that had never heard of MOVEit. Your exposure is not only your vendors; it is your vendors' vendors. Tracking sub-processors is not paranoia, it is the only way to know who actually touches your data.
Sources
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].