HackingVulnerability ExploitCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Lemoore Union High School District
bd_97b6736d0e17cab5 · schema v1 · pii pii-v1
Full breach record for Lemoore Union High School District →Lemoore Union High School District notified parents that an unauthorized individual exploited a vulnerability in the Aeries Student Information System in late November 2019. The exploit allowed access to parent and student names, home addresses, phone numbers, email addresses, and hashed passwords. The district required password changes and installed a software patch provided by Aeries. Law enforcement investigated and identified the suspect.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-193515
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 27, 2020
- Raw hash
- 6d75df53711758fc4c15df8489e2e87260adbb96d430f4ce52a3103acd71bc9e
Reporting entity
- Name
- Lemoore Union High School Districtnorm: lemoore union high school district
- Domain
- luhsd.k12.ca.us
Victim entity
- Name
- Lemoore Union High School Districtnorm: lemoore union high school district
- Domain
- luhsd.k12.ca.us
Incident
- Discovered
- Nov 25, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via Aeries
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 39 weeks(276 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.