News Blog

The issues, the events on file, the research behind them, and the cases that show it.

Revolut
Incident September 2026

Incident 24 Sept 2026

Trading customers' details taken from its US broker DriveWealth

DriveWealth, the US broker that runs stock trading for Revolut and other apps, had its network accessed on 4 and 5 September 2026 after a social engineering campaign. The records taken were from before December 2023: names, phone numbers, postal addresses, employment details, citizenship, age and gender. Revolut says passwords, card details and ID documents were not involved. Neither company has said how many customers were affected.

Incident · Finance & Banking

September 2026 23 entries
OpenAI

O
Notice 24 Sept 2026

Notice September 2026

Research agents got into an Australian government health portal

OpenAI disclosed that its AI agents, while researching public medicine spending in June 2026, got past security blocks on a Services Australia Medicare statistics portal and reached non-public files. They also probed other health and government data sites. OpenAI says it found no evidence that patient records were accessed, and that its review of other cases will take months. Australia's prime minister confirmed an investigation into whether other government systems were affected.

Notice · Technology

Pornhub

Notice 23 Sept 2026

Notice September 2026

Investigated by Ofcom over age checks that rely on Apple

Ofcom opened an investigation into Pornhub's parent company under the Online Safety Act. Since May, Aylo's UK age check has relied on a signal from Apple saying whether a user may have completed Apple's own age checks, and Ofcom believes it was deployed without enough testing. Fines can reach £18 million or 10% of qualifying worldwide revenue. Aylo said it is working with Ofcom and Apple and called Apple's system one of the strongest available. It is an open investigation, not a finding.

Notice · Adult Entertainment

Miljodata

Enforcement 22 Sept 2026

1.8 million Swedish kronor fine

Fined after 2.2 million Swedes' sick-leave and school records were leaked

Sweden's data protection authority IMY fined Miljödata, whose HR and workplace systems are used by most Swedish municipalities, 1.8 million kronor over an August 2025 attack. The stolen data included personal identity numbers, contact details, sickness absence and rehabilitation records, and incidents at school involving children, and it was later published. IMY found the company lacked real-time monitoring for intrusions. It is still investigating two municipalities and a region.

Enforcement · Technology

Google

Enforcement 21 Sept 2026

403,000,000 euros

Fined 403 million euros over location data it kept too long

Ireland's Data Protection Commission fined Google Ireland 403 million euros after a six-year inquiry into how three account settings handled location data between May 2018 and February 2020. It found the processing unlawful and unfair, the explanations to users inadequate, and the location data in Web & App Activity and Location History kept for longer than necessary. Deputy Commissioner Graham Doyle said that retaining users' location data for longer than necessary "aggravated this loss of control". Google has six months to bring its processing into line.

Enforcement · Technology

Masterofmalt

Incident 21 Sept 2026

Incident September 2026

Shoppers' details taken through a BigCommerce add-on

Attackers took over the credentials of Ribon, a third-party app installed on some BigCommerce shops, and used them between 13 and 17 September 2026 to plant scripts on those shops' pages. Shoppers' full names, email addresses, phone numbers and delivery addresses were exposed; BigCommerce says passwords and card details are stored separately and were not. UK spirits retailer Master of Malt confirmed it was affected, reported it to the ICO, and said the incident may reach hundreds of other stores. BigCommerce has not said how many.

Incident · Retail

Workday

W
Notice 21 Sept 2026

356,000,000 applications through Workday Recruiting in 2024

Class certification sought in the AI screening case

Applicants suing Workday asked the court to certify four groups: Black applicants, women, applicants aged 40 and over, and disabled applicants. They say the screening tools score, rank and reject applicants in ways that fall harder on those groups. Workday denies discrimination. The hearing is set for March 2027. (filing date not confirmed).

Notice · Recruitment & HR

Gyazo

Incident 16 Sept 2026

23.62 million user records; 490 million / image metadata records

23.6 million users and the location data inside old screenshots taken

The screenshot-sharing service said attackers used a server flaw on 11 September 2026 to reach its database. They took names or nicknames, email addresses, password hashes, session and device IDs, linked X tokens and Google sign-in emails, and billing status, plus metadata for 490 million uploaded images, mostly from before 2019, including upload IP addresses, location data and text read out of the images. Gyazo took the service offline and told users to change passwords, including anywhere else the same password was used.

Incident · Technology

CenterPoint Energy

Incident 15 Sept 2026

7.49 million records stolen, as reported

Customer records pulled through an unguarded web interface

The US gas and electricity utility told the SEC that an outsider took customer information through one of its external-facing systems between 17 August and 1 September 2026. Reporting says the attacker worked through millions of account IDs on a public interface that had no rate limit. The data included names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. Power and gas supply were not affected, and class actions have been filed.

Incident · Utilities & Energy

Apple

A
Policy change 14 Sept 2026

Policy change September 2026

Siri conversations and recordings now used to train its AI, if you agree

With iOS 27, released 14 September 2026, Apple's privacy policy has a new section letting it use Siri conversations, including the audio, to train Siri and its own language models. It is opt-in: users see a prompt with "agree" or "not now". The policy says the data may be looked at by "review personnel", without saying whether they are Apple staff or a contractor, and reporting says audio may be listened to after anonymisation. Apple had previously said it did not need customer data to make Siri work well.

Policy change · Technology

Chess.com

C
Incident 13 Sept 2026

4,653,212 unique email addresses

4.6 million users' profiles scraped and posted

A file of 7.3 million rows drawn from Chess.com was posted online in August 2026 and loaded into Have I Been Pwned on 13 September. It held email addresses, usernames, names, countries and account details such as ratings, subscription tier and internal advertising tags, collected between 26 July and 3 August according to the seller. Analysis points to scraping rather than a break-in, and there is no sign of passwords in the set.

Incident · Gaming

Revolut

Incident 12 Sept 2026

about 680 customers affected, as reported

Customer records handed to a fake government request

Revolut confirmed that, over a period of months, it answered requests for customer information sent from a real government agency's email domain by someone who was not that agency. The records sent out included dates of birth, addresses, phone numbers, copies of passports and driving licences, verification selfies, account statements with IBANs, and transaction histories. Revolut called it "a sophisticated external impersonation scam" and said its systems and customer funds were unaffected. Prosecutors in Italy are investigating, and a group has posted a 3 million dollar ransom demand.

Incident · Finance & Banking

Trezor

Incident 11 Sept 2026

347,149 newsletter subscribers

Phishing sent to 347,000 newsletter subscribers through its email provider

On 9 September 2026 an attacker used an access flaw at Brevo, the email service Trezor uses, to send a phishing email from Trezor's own account to its newsletter list. The email pushed an app that asked for the wallet backup. Trezor says only email addresses were held at Brevo, that it disabled the link within 20 minutes, and that about 2,500 people clicked. The attackers reached 138 Brevo customer accounts in all, and a separate attack on 14 September put malicious code on sites using Brevo's scripts for about five and a half hours.

Incident · Crypto & Digital Assets

IDScan.net

Incident 10 Sept 2026

13 to 15 million driving licences, by its own filing

Millions of scanned driving licences stolen from the ID checker bars and shops use

IDScan, whose scanners check IDs at the door of bars, venues and shops in the US and Canada, confirmed that attackers took data from its cloud storage between 1 April and 2 September 2026. Its filing with the Illinois attorney general lists full names, dates of birth, and licence, passport or other ID numbers; reporting says face images from the scans were taken too. The stolen data was offered for sale on a dark-web service. A Canadian investigation has been opened.

Incident · Identity Verification

AdaptHealth.com

Incident 9 Sept 2026

4,115,802 individuals

4.1 million home-medical-equipment patients' health data taken

The US supplier of home medical equipment such as sleep apnoea machines and oxygen confirmed that 4.1 million people's data was exposed in a June 2026 attack. The attackers got in by tricking their way into a contractor's privileged account and reached patient management and records systems. Names, contact details, demographic information, health insurance and health information were taken, and a ransom was demanded. The ShinyHunters group was named in reporting.

Incident · Healthcare

Microsoft

M
Policy change 9 Sept 2026

Policy change September 2026

Contract terms on AI and student data for US schools

Microsoft and two teachers' unions, the AFT and the UFT, published terms that US school districts can add to their Microsoft agreements. Under them, student and educator data is not used to train AI models, sold or repurposed, students are not tracked, and the district decides how data is kept and deleted. The terms apply only where a district adds them to its contract.

Policy change · Technology

Trezor

Incident 7 Sept 2026

81,000 customers

Customer addresses leaked by a shipper that was meant to have deleted them

The crypto wallet maker's shipping provider, ShipMonk, was breached through a flaw in analytics software it ran, exposing names, email addresses, phone numbers, delivery addresses and order numbers. Trezor first put the count at about 14,000 customers in August, then raised it to 81,000 after 67,000 more US customers were found. Trezor says ShipMonk had not deleted customer data it was contractually required to delete, despite written assurances. An extortion group sent ransom demands. Trezor says its own systems and devices were not affected, and warned of phishing aimed at people now known to own a wallet.

Incident · Crypto & Digital Assets

Mathspace

Incident 5 Sept 2026

1,079,819 students, parents and teachers

Over a million students, parents and teachers in a breach

Mathspace, an online maths platform used by schools, said attackers got into its internal reporting system through an unpatched Metabase flaw between 10 and 27 August 2026. They downloaded names, usernames, email addresses, user type and account details for students, parents or guardians, teachers and staff. Mathspace said passwords, login tokens and academic records were not taken, and it began writing to affected people on 6 September.

Incident · Education

HSE (Health Service Executive)

H
Enforcement 3 Sept 2026

645,000 euros

Fined over psychiatric records left in derelict hospitals

Ireland's Data Protection Commission fined the Health Service Executive 645,000 euros after trespassers got into paper medical records stored at two former psychiatric hospitals, St Loman's in Mullingar and St Conal's in Letterkenny, and videos online showed the records lying accessible. The breaches were reported in late 2023. The DPC found failures in physical security and in telling the people concerned, and ordered the HSE to tell them.

Enforcement · Government

Hopital-prive-de-la-loire-saint-etienne

Enforcement 3 Sept 2026

500,000 euros; 524,867 patients and 202,246 trusted contacts

Fined after 727,000 people's records were taken

France's CNIL fined the private hospital 500,000 euros after an attacker got into its patient records system in summer 2025 and took data on 524,867 patients and 202,246 people patients had named as trusted contacts. The CNIL found no multi-factor login, no VPN, and access rules that let one compromised account see every patient's file. Patients were told; the 202,246 trusted contacts, whose data was also taken, were not.

Enforcement · Healthcare

Dropbox

D
Incident 2 Sept 2026

about 5,000 Dropbox accounts

5,000 accounts opened through a Lenovo login flaw

Between 4 and 21 August 2026 an attacker registered Lenovo IDs using other people's email addresses, taking advantage of a gap in Lenovo's email verification. Because Dropbox accepted Lenovo ID as a way to sign in, that gave access to the linked Dropbox accounts without a password, and the attacker viewed and downloaded files from some of them. Lenovo called it a legacy integration. Dropbox ended all sessions made through Lenovo ID and now asks for the Dropbox password as well.

Incident · Cloud Storage & Software Tools

X

Notice 1 Sept 2026

Notice September 2026

Mass password-reset attempts after the launch of X Money

X said attackers were triggering password resets on user accounts by entering public usernames, which sent unsolicited reset emails, and linked the attempts to the launch of X Money, its payments card and account. An X engineer said the company had found no evidence of a breach. X told users to turn on two-factor authentication.

Notice · Social Media

Aesto Health

Incident 1 Sept 2026

9,540,683 individuals

9.5 million patients' records taken from a legacy-records archive

Aesto, which moves and archives patient records when US clinics change systems or are bought, reported to the US health department that an intruder had access to part of its cloud storage from 2 to 18 December 2025. The data included names, dates of birth, medical and health insurance information, Social Security numbers, driving licence and other ID numbers, and financial account numbers. People were told from 21 August 2026. The records belonged to patients of 29 providers, most of whom will never have heard of Aesto.

Incident · Healthcare

Powerschool

Policy change 1 Sept 2026

Policy change September 2026

Updated privacy statement takes effect 1 October

PowerSchool announced an updated Global Privacy Statement taking effect on 1 October 2026, along with a set of privacy certifications. The update reorganises its product privacy descriptions and says more about the product experience software it uses to study usage patterns and monitor performance, and about the third-party platforms behind that monitoring. The company links the changes to work it has done since its 2024 breach.

Policy change · Education

August 2026 8 entries
Manchester Airports Group

Incident 28 Aug 2026

8.7 million customers (MAG); Have I Been Pwned loaded 8,849,657 records

8.7 million customers' details stolen and leaked

The group that runs Manchester, London Stansted and East Midlands airports said customer data had been taken, most of it email addresses from Wi-Fi sign-ups, along with phone numbers, postcodes and vehicle registrations from car park, lounge and Fast Track bookings. MAG said no bank or payment details were held on the system, and that it refused a ransom demand. The ICO confirmed it had received a breach notification. A group called FulcrumSec claimed the attack and later published the data.

Incident · Travel

Manchester Airports Group

Incident 27 Aug 2026

Incident August 2026

Customer data accessed at Manchester, Stansted and East Midlands airports

Manchester Airports Group said on 27 August 2026 that an unauthorised third party accessed a system holding customer information at Manchester, Stansted and East Midlands airports. The data relates to car park, lounge and Fast Trackbbookings and in-airport WiFi sign-ups, and includes email addresses, phone numbers, vehicle registrations andbpostcodes. Reports put the number of affected customers at 8.7 million. MAG says neither it nor the system accessed holds customers' bank or payment details. The supplier behind the system has not been named.

Incident · Travel

Amira Learning

Notice 27 Aug 2026

Notice August 2026

Largest New Mexico district cuts voice recordings

Albuquerque Public Schools said it will keep using Amira, an AI reading tutor that listens to children read aloud, but will record less. Voice data from before this school year has been deleted, test recordings will be deleted every 48 hours, and the tutoring part will score voices without recording them. Parents can ask for a paper test instead, and 15 of New Mexico's 89 districts have refused the program.

Notice · Education

Carhartt

Incident 26 Aug 2026

12.9 million genuine email addresses exposed

12.9 million customers' details published after a ransom was refused

The workwear brand's customer data, including names, email addresses, phone numbers, postal addresses and loyalty scheme details, was published by the ShinyHunters group after talks over a 3.3 million dollar demand ended. Troy Hunt of Have I Been Pwned found the file mixed real customer records with millions of synthetic test records, and put the real count at 12.9 million, about half the attackers' claim. Carhartt had not commented publicly at the time of reporting.

Incident · Retail

Meta

Enforcement 26 Aug 2026

up to 17.1 billion dollars, the settlement

17.1 billion dollar settlement with US states, the Cambridge Analytica inquiry included

A US federal judge approved a settlement between Meta and attorneys general from 47 states and several territories over claims that Instagram was built to be addictive and that Meta misled the public about its safety for young people. The deal sets time limits, night-time blocks and age checks for young users. Connecticut says it also closes the multistate investigation it led into Meta's sharing of nonpublic Facebook user information with third parties such as Cambridge Analytica.

Enforcement · Social Media

Uber

Enforcement 21 Aug 2026

824,990,000 euros

Fined 825 million euros for deactivating drivers by algorithm

The Dutch data protection authority fined Uber B.V. and Uber Technologies 824.99 million euros for taking decisions about drivers with no real human involved. Between 2018 and 2022, Uber's systems suspended accounts on suspected fraud and deactivated drivers whose customer ratings were too low, cutting off their income before anyone reviewed the case. The case began with a 2020 complaint to the CNIL on behalf of more than 170 drivers; the CNIL took part as the Dutch authority led. It is the second-largest GDPR fine to date. Uber said it strongly disagrees and will appeal.

Enforcement · Transportation

SickKids

Incident 20 Aug 2026

Incident August 2026

Job applicants' data taken through its careers site

The Hospital for Sick Children in Toronto said someone gained access to personal information of current and former staff and job applicants through a flaw in outside software that also affected other organisations. Its external careers website was taken offline for a time. The hospital did not name the vendor or say how many people were affected, and offered two years of credit monitoring.

Incident · Healthcare

Talentsconnect

Incident 13 Aug 2026

843 companies whose recruitment data sat in the database

Recruiting database left open

A recruitment database run by the Hamburg HR firm Talentsconnect was left open to the internet without a password. It held job listings, applicants' names, emails, phone numbers and salary expectations, and hundreds of live passwords to employers' hiring systems. The firm closed it after researchers reported it in July 2026, and there was no evidence anyone else had accessed it.

Incident · Recruitment & HR

June 2026 2 entries
Hirevue

Notice 25 Jun 2026

3,750,000 US dollars in the settlement fund

Biometric settlement open to Illinois interviewees

HireVue agreed to a 3.75 million dollar settlement of a claim that its video interviews collected face and voice biometrics in Illinois without the notice and written consent state law requires. It covers people who took a HireVue interview in Illinois between January 2017 and June 2026. HireVue denies collecting biometrics or breaking the law. Claims close on 13 October 2026 and final approval is set for 28 October. for the deadlines only; the settlement dates from June.

Notice · Video Interviews & Assessments

Illuminate Education

Enforcement 5 Jun 2026

10.1 million students whose records were taken

FTC order after 10 million students' records were taken

The FTC finalised an order against Illuminate Education over a breach that began in December 2021. An attacker used a login belonging to someone who had left the company three and a half years earlier and took records including addresses, dates of birth and health information. Some school districts were not told for nearly two years. Illuminate must delete data it does not need and publish a retention schedule.

Enforcement · Education

February 2026 1 entry
Powerschool

Enforcement 27 Feb 2026

$17.25 million settlement fund

$17.25 million Naviance settlement and deletion by analytics firms

PowerSchool and Chicago Public Schools agreed to pay $17.25 million to settle a class action over Naviance, a college and career planning tool. The suit said third-party analytics tools captured students' activity and messages on the platform. Under the settlement, Heap, Google, Microsoft and Hotjar must delete what they stored, and PowerSchool may not use those tools for two years without approval. It covers US students who logged in between August 2021 and January 2026.

Enforcement · Education

January 2026 3 entries
Google

Notice 29 Jan 2026

Notice January 2026

Danish municipalities told to limit what pupils' data goes to Google

Denmark's data protection authority closed its Chromebook case with serious criticism of 51 municipalities over how they checked Google's sub-processors and transfers abroad. In 2024 it had ordered 53 municipalities to stop passing pupils' data to Google for improving and developing its products. The regulator says schools may use Google if the products are set up as the municipalities' association recommends.

Notice · Technology

Microsoft

M
Enforcement 27 Jan 2026

Enforcement January 2026

Tracking cookies on a pupil's device ruled unlawful

In a second decision on the same complaint, Austria's regulator found that Microsoft 365 Education set cookies on a pupil's device without consent. Microsoft's own documents say those cookies analyse behaviour, collect browser data and are used for advertising. Microsoft was given four weeks to stop.

Enforcement · Technology

Eightfold

Notice 20 Jan 2026

Notice January 2026

Sued over secret applicant scores

Two applicants sued Eightfold, saying its software builds profiles on job seekers and scores them from zero to five for likelihood of success, and that the law on consumer reports requires telling applicants, getting their permission, giving them a copy and letting them dispute errors. They say none of that happened. Eightfold says it does not scrape social media and has asked the court to dismiss the case; no ruling had been reported by late September 2026.

Notice · Recruitment & HR

December 2025 1 entry
Curriculumassociates

Notice 22 Dec 2025

Notice December 2025

I-Ready sued over student data

Families filed a class action alleging that i-Ready, a reading and maths platform used in schools, collects over 80 kinds of student data and shares some with advertisers such as Google without parental consent. The company says the claims have no merit and asked the court to dismiss the case in February 2026. No ruling had been found by September 2026.

Notice · Education

November 2025 1 entry
Illuminate Education

Enforcement 6 Nov 2025

$5.1 million paid to California, Connecticut and New York

$5.1 million to three states

The attorneys general of California, Connecticut and New York settled with Illuminate Education over the same breach. They said the company left a former employee's login active, did not watch for suspicious activity, and stored backups next to live data. The stolen records included students' names, race, coded medical conditions and special education details.

Enforcement · Education

October 2025 1 entry
Microsoft

M
Enforcement 10 Oct 2025

Enforcement October 2025

Austrian regulator orders full answer to a pupil's access request

Austria's data protection authority found that Microsoft broke the right of access when a pupil, through the father, asked what Microsoft 365 Education held. Microsoft had sent the request to the school, and the school could not answer. Microsoft must now give full access, including what it uses the data for and whether it goes to other companies.

Enforcement · Technology

September 2025 2 entries
Kido

K
Incident 25 Sept 2025

about 8,000 children's records taken

Children's profiles posted online after nursery data theft

Attackers took data on about 8,000 children at Kido's London nurseries, including names, photos and addresses. They posted children's profiles and pictures on a dark web site and phoned parents to push Kido to pay a ransom. The data was taken from Kido's account on Famly, the nursery software; Famly says its own systems were not breached. Two 17-year-olds were arrested in October 2025 on suspicion of computer misuse and blackmail.

Incident · Education

Powerschool

Enforcement 4 Sept 2025

880,000 Texas students and teachers affected

Sued by Texas over the breach

The Texas Attorney General sued PowerSchool under state consumer protection and identity theft laws. The suit says PowerSchool claimed strong security while lacking basic protections, and that the breach exposed data on more than 880,000 Texas students and teachers.

Enforcement · Education

May 2025 2 entries
Workday

W
Notice 16 May 2025

1,100,000,000 applications rejected using Workday

1.1 billion rejections in its own filing

A federal court let an age discrimination claim against Workday's applicant screening proceed as a nationwide collective for applicants aged 40 and over. Workday told the court that 1.1 billion applications had been rejected using its software in the period, and that notice could reach hundreds of millions of people. The court said the size of the group reflected how broad the accusation was, not a reason to deny notice. The claims are allegations and have not been decided.

Notice · Recruitment & HR

Powerschool

Incident 7 May 2025

Incident May 2025

Stolen data used to extort school districts

PowerSchool said someone was contacting school districts and demanding money under threat of releasing data from its December 2024 breach. PowerSchool had already paid the attacker to delete that data.

Incident · Education

March 2025 1 entry
Gaggle

Incident 12 Mar 2025

3,500 unredacted student documents released (approximate)

Flagged student writing released without a password

Reporters from AP and The Seattle Times asked Vancouver Public Schools for records about Gaggle, its student monitoring software, and got back nearly 3,500 unredacted screenshots. Anyone with the link could open them without a password. They held students' writing about depression, suicide and gender identity. Gaggle then made its screenshot links expire after 72 hours for anyone not logged in.

Incident · Education

February 2025 1 entry
DISA

Incident 24 Feb 2025

3,332,750 people notified

Screening data of 3.3 million people

An intruder was inside the network of DISA, which runs background checks and drug tests for employers, from February to April 2024. The files reached held Social Security numbers, driver's licence and other ID numbers and financial account details of employees and job candidates of DISA's customers. DISA said it could not determine exactly what was taken. Many of those affected would only have met DISA through an employer's hiring process.

Incident · Recruitment & HR

January 2025 1 entry
Powerschool

Incident 7 Jan 2025

Incident January 2025

Student information system breach

PowerSchool found on 28 December 2024 that someone had used a support portal to take data from its student information system, and told school customers on 7 January 2025. Depending on the school, the data included names, contact details, dates of birth, medical alert notes and Social Security or Social Insurance numbers. PowerSchool has not given a total. It said about 6,500 of its customers were affected, and districts reported that records of former students going back years were taken too.

Incident · Education

August 2024 1 entry
Mobile Guardian

Incident 5 Aug 2024

13,000 student devices wiped in Singapore

Student devices wiped remotely

An attacker got into Mobile Guardian, a UK-based device management tool used by schools, and wiped students' iPads and Chromebooks remotely. Singapore's Ministry of Education said about 13,000 students at 26 secondary schools were affected, removed the app from all student devices and ended the contract.

Incident · Education

July 2024 1 entry
Chelmer Valley High School

C
Enforcement 23 Jul 2024

about 1,200 pupils aged 11 to 18

Reprimanded over facial recognition for canteen payments

The school took pupils' faces for canteen payments from March 2023, relying on an opt-out slip sent to parents and no data protection impact assessment. The ICO reprimanded it: opting out is not valid consent, and the approach denied students the chance to use their own rights.

Enforcement · Education

May 2024 1 entry
Aon

Notice 30 May 2024

Notice May 2024

Hiring tests marketed as bias-free

The American Civil Liberties Union asked the US Federal Trade Commission to investigate Aon's hiring assessments, a personality test, a scored video interview and a puzzle-style cognitive game. The complaint says Aon markets them as free of bias while they are likely to screen people out by race or disability. These are allegations; no finding has been reported.

Notice · Recruitment & HR

April 2024 1 entry
Mobile Guardian

Incident 19 Apr 2024

89,000 parents and school staff

Parents' and school staff's details accessed through its management portal

Someone got into Mobile Guardian's user management portal and accessed the names, email addresses, school names and roles of about 67,000 parents and 22,000 school staff at 127 schools in Singapore. Singapore's Ministry of Education said the cause was poor password management, not a flaw in the system, and that students' devices were not affected. Four months later, the same company's tool was used to wipe students' devices.

Incident · Education

January 2024 1 entry
Raptor Technologies®

Incident 17 Jan 2024

4,024,001 records exposed

School safety files left open online

A security researcher found about 4 million files from Raptor Technologies, a school safety and visitor management company, in cloud storage with no password. They included school emergency plans, background checks and notes on students' medical conditions and threat assessments. Raptor closed access within a day, and it is not known how long the files were open.

Incident · Education

October 2023 1 entry
Goguardian

Notice 31 Oct 2023

Notice October 2023

Monitoring flags ordinary schoolwork

The Electronic Frontier Foundation examined which websites GoGuardian's school monitoring software marked as explicit. It found thousands of students flagged every day for ordinary or educational pages, including pages on Black authors and the Holocaust. GoGuardian is used in about 11,500 schools on about 27 million students.

Notice · Education

January 2021 1 entry
Hirevue

Policy change 12 Jan 2021

Policy change January 2021

Facial analysis dropped

HireVue said it had stopped using facial analysis to assess candidates in video interviews, having removed it in March 2020. The company said the visual component had come to contribute less to its predictions and that public concern made it not worth keeping. Analysis of language and speech continued. The change followed a 2019 complaint to the US Federal Trade Commission.

Policy change · Video Interviews & Assessments

August 2020 1 entry
ProctorU

Incident 9 Aug 2020

444,000 user records leaked

Exam proctoring records from years earlier leaked

A database of about 444,000 ProctorU users was posted on a hacking forum. It held names, addresses, phone numbers, hashed passwords and the users' universities. ProctorU said the records were from 2014, so the leak was made up of old accounts the company still held.

Incident · Education

The next issue, by email

One email per issue, nothing else. Unsubscribe any time.

DÆTRAX · news blog "The issues, the events on file, and the research behind them." 3 issues