← All incidents
Resolved, last updated 2024
Education data clearinghouseMOVEitClopSupply chainSub-processor

National Student Clearinghouse MOVEit Breach

Mid 2023. The signature supply-chain breach of 2023. One file-transfer flaw cascaded across nearly 900 institutions, the textbook argument for tracking your vendors’ sub-processors.

What happened

The Clop gang exploited a zero-day in the MOVEit file-transfer tool to steal data from the National Student Clearinghouse, which handles enrollment and degree records for nearly every US institution. The flaw was not in the Clearinghouse itself; it was in a tool the Clearinghouse used. The breach was later settled for $9.95 million.

Confirmed exposed

  • Names, dates of birth, contact information
  • Social Security numbers and student ID numbers
  • Enrollment, degree, and course-level records

Confirmed not exposed

  • Exposure depended on which records each institution had submitted to the Clearinghouse

Nearly 900 colleges and universities were affected; the Clearinghouse notice also reached high schools and education organizations. The Maine AG filing named 51,000+ individuals.

Why it belongs in this library

One vendor's file-transfer flaw cascaded across hundreds of institutions that had never heard of MOVEit. Your exposure is not only your vendors; it is your vendors' vendors. Tracking sub-processors is not paranoia, it is the only way to know who actually touches your data.

Sources

  1. BleepingComputer — National Student Clearinghouse data breach impacts 890 schools (2023)
  2. Higher Ed Dive — MOVEit breach hit nearly 900 colleges, says National Student Clearinghouse (2023)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

National Student Clearinghouse MOVEit Breach: Mid 2023 | Ask Before You App