HackingEducationEducationVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryN-DayCREDENTIALSIDENTITY_BASICAUTHENTICATIONEDUCATIONLowResolved
Corning Union High School District
bd_62731d8c637aca9b · schema v1 · pii pii-v1
Full breach record for Corning Union High School District →Corning Union High School District notified families of a data breach involving its third-party Student Information System provider, Aeries Software, Inc. Unauthorized access to the Aeries SIS was first detected in late November 2019; an expanded investigation in March 2020 confirmed exposure of parent and student login information, physical addresses, email addresses, and password hashes. Aeries deployed security patches and the district reset portal passwords.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190790
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2020
- Raw hash
- 26879fc2175a33333c85ac1dc18b2077683a7c364666b398f6d45509746ab236
Reporting entity
- Name
- Corning Union High Schoolnorm: corning union high school
- Domain
- corninghs.org
Victim entity
- Name
- Corning Union High School Districtnorm: corning union high school district
- Domain
- cuhsdistrict.org
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSIDENTITY_BASICAUTHENTICATIONEDUCATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing ApplicationT1110 Brute Force
- Threat actor
- External
- Third party
- via Aeries Software, Inc. (DBA Eagle Software)
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.