Student loan data breach leaks 2.5 million social security numbers

Bad actors may have gained access to millions of users’ information between June and July

Add bookmark
Student loan data breach leaks 2.5 million social security numbers

A data breach on student loan servicer Nelnet Servicing has caused the confidential information of  over 2.5 million users to be leaked. Nelnet Servicing provides technology services including a website portal to two student loan companies, Edfinancial and OSLA services.

On 21 July 2022, Nelnet contacted the two student loan servicing companies it provides technology services to about a cybersecurity vulnerability, which was discovered due to some "suspicious activity". Once the vulnerability was discovered, Nelnet worked to secure its information system and launch an investigation into the incident.

It was concluded by the investigation on 17 August that, due to the vulnerability, student loan account registration information including name, address, email address, phone number and social security number, was accessible to an unknown third party staring in June and ending on 22 July 2022. Following this discovery, Nelnet Servicing notified the US Department of Education and law enforcement.

In a notice of the data breach provided to the Office of the Maine Attorney General, Nelnet said it is “providing impacted individuals with guidance on how to better protect against identity theft and fraud”.  

The company is also providing individuals affected by the breach with access to credit monitoring services for 24 months, as well as providing notice of the incident to all relevant state and federal regulators and the credit reporting agencies TransUnion, Equifax and Experian. 


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62ff6fc7b962cc3fb47d87ba","name":"Data breaches on gaming sites are becoming more common","description":"Cyber Security Hub takes a deep dive into why gaming sites may be a target for hackers","file":null,"url":"\/attacks\/articles\/data-breaches-on-gaming-sites-are-becoming-more-common"},{"id":"62f4e94acbeb1317b057d394","name":"IOTW: Twilio suffers data breach following phishing attack","description":"The company\u2019s employees were directly targeted by a phishing attack disguised to look like it came from Twilio\u2019s IT department","file":null,"url":"\/attacks\/news\/iotw-twilio-suffers-data-breach-following-phishing-attack"},{"id":"5d9b8549d1d92e0ea916c6d2","name":"IOTW: Multiple Yahoo data breaches across four years result in a $117.5 million settlement","description":"Phishing And Nation State Attacks Lead To Mega-Breach Of Former Leading Email Provider","file":null,"url":"\/attacks\/articles\/incident-of-the-week-multiple-yahoo-data-breaches-across-4-years-result-in-a-1175-million-settlement"},{"id":"62a0cf741ffc11648c662d2a","name":"IOTW: US healthcare group data breach affects two million","description":"A data breach at Shields Health Care Group affects two million patients","file":null,"url":"\/data\/news\/iotw-us-healthcare-group-data-breach-affects-two-million"},{"id":"61a9ee78d1d92e03fb563c3f","name":"IOTW: Panasonic confirms data breach","description":"Japanese electronics manufacturer suffers illegal intrusion to file servers","file":null,"url":"\/attacks\/articles\/iotw-panasonic-confirms-data-breach"}],"featured_content_portal_embedded":null}" >