HackingEducationEducationVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Customer Data InvolvedN-DayDelayed DiscoveryIDENTITY_BASICAUTHENTICATIONCREDENTIALSLowContained
Inglewood Unified School District
bd_daec79d540c75e7e · schema v1 · pii pii-v1
Full breach record for Inglewood Unified School District →Inglewood Unified School District notified California parents and guardians that an unauthorized individual exploited a vulnerability in the Aeries Student Information System in late November 2019. The perpetrator may have accessed parent/student names, home addresses, phone numbers, email addresses, and hashed passwords. Aeries notified the District on April 27, 2020. The vulnerability was remediated by installing a software patch provided by Aeries. Law enforcement investigated and the suspect was reportedly taken into custody.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190498
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2020
- Raw hash
- 1865e8c51496d58597b5e6e84e79d0e68df28b8debe8fd2838530fc34b96b61d
Reporting entity
- Name
- Inglewood Unified School Districtnorm: inglewood unified school district
- Domain
- inglewoodusd.com
Victim entity
- Name
- Inglewood Unified School Districtnorm: inglewood unified school district
- Domain
- inglewoodusd.com
- Industry
- Educationllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- May 5, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICAUTHENTICATIONCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Third party
- via Aeries Student Information System
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.