Only 7% of ransomware-hit organizations around the world were able to recover all their stolen data after paying the ransoms sought by their attackers.
Infiltration of PowerSchool's student information systems via stolen customer support portal credentials has primarily impacted the Toronto District School Board, which had data from over 1.48 million students and over 90,000 teachers exfiltrated, followed by the Peel District School Board, which is also in Canada, and the Dallas Independent School District.
In a post on its leak site on Wednesday, RansomHub asserted that it was able to exfiltrate 400 GB of data from American Standard's network servers while threatening the firm to enter ransom payment negotiations in just over five days.
The study, which analyzed tens of thousands of prompts, revealed that nearly 8.5% of business users may have disclosed sensitive information, with 46% of these incidents involving customer data such as billing and authentication details.
Aside from the possible compromise of names, birthdates, genders, home addresses, phone numbers, and health card digits, TDSB students enrolled beginning Sep. 2017 may have also had their parent, guardian, or caregiver contact details and certain medical data leaked.
Information discovered within the unsecured database included not only bills, repayment schedules, mailing lists, settings, and snapshots detailing names, credit limits, and email addresses, but also a spreadsheet with data from 56,864 individuals, which may include current and prospective clients, as well as blocked accounts.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.