Breach

Cyberattack compromises Pearson data

Plain code with the word "cyberattack" in red.

Major UK multinational education services provider Pearson had mostly legacy corporate and customer information stolen following a cyberattack, BleepingComputer reports.

More robust security monitoring and authentication mechanisms have already been implemented amid an ongoing investigation into the incident, which has been confirmed not to have impacted employee data, according to a Pearson spokesperson. "We will be sharing additional information directly with customers and partners as appropriate," said the spokesperson. Additional details regarding the incident continue to be lacking but the disclosure comes after Pearson was reported by sources to have had its developer compromised through an exposed GitLab Personal Access Token in January. Attackers were noted to have leveraged the token to infiltrate Pearson's source code and obtain hard-coded credentials, which were later used to pilfer troves of internal network and cloud infrastructure data. Pearson's acknowledgment of an attack against its subsidiary PDRI in January is also thought to be related to the intrusion.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Attack Vector

You can skip this ad in 5 seconds