HackingEducationEducationVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedDownstream VictimsN-DayIDENTITY_BASICAUTHENTICATIONEDUCATIONLowResolved
Santa Barbara Unified School District
bd_0885f01d410c5843 · schema v1 · pii pii-v1
Full breach record for Santa Barbara Unified School District →Santa Barbara Unified School District notified families on May 20, 2020 of unauthorized access to the Aeries Student Information System, a third-party vendor used by hundreds of California districts. The breach, discovered in late November 2019, may have exposed student IDs, parent and student emails, physical addresses, and hashed passwords. Aeries patched the vulnerability in December 2019 and perpetrators were taken into custody.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190249
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 20, 2020
- Raw hash
- 9dc247fd68cbf28380dd4b372044f8a5eeb2ff7a13a6ad1399b7039915be8104
Reporting entity
- Name
- Santa Barbara Unified School Districtnorm: santa barbara unified school district
Victim entity
- Name
- Santa Barbara Unified School Districtnorm: santa barbara unified school district
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 20, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICAUTHENTICATIONEDUCATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Third party
- via Aeries Software
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.