The breach, which occurred between April and September 2023, was the result of credential-stuffing attacks that compromised the data of 6.9 million customers, including sensitive genetic ancestry information.
The data exposure occurred through a sophisticated vishing attack where a threat actor, posing as IT support, tricked a contact center agent into visiting a malicious website.
The breach, which Miinto reported to the police and data protection authorities, may have compromised customer names, email addresses, physical addresses, and phone numbers.
The breach, initially disclosed by MBI in June, saw ShinyHunters leak the stolen data after the Christian college apparently did not meet their extortion demands.