This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 2493 To_xml

SUMMARY

Unknown security breach exposes 130,000 students names and Social Security numbers
Records 130,000
Record Types SSN NAA DOB
Breach Type Hack
Data Family Electronic
Source Outside
Organization Eastern Washington University
Other Organizations None
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: kirniki

TIMELINE

DateEvent
None. Add Data Incident Occurred
None. Add Data Incident Discovered By Organization
2009-12-31 Organization Reports Incident
None. Add Data Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
178,000 2004-03-17 San Diego State University
380,000 2004-05-07 University of California San Diego
120,000 2005-03-17 Boston College
72,000 2005-06-28 University of Connecticut

MAP OF INCIDENT LOCATION

Address: 526 5th St, Cheney, WA 99004, USA
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $7,800,000.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

COMMENTS

by Anonymous on 2010-01-02 (2 months ago)

done through local file inclusion from there i was i mean the hacker was able to execute code remotly and upload a php shell, gain root and sl the sql db, and no the hacker is not going to use the info he has at all for malicious purposes. he had even notified the server admins 4 weeks before even exploiting the site due to boredom.

New Comment

simple_captcha.jpg
(type the code from the image)

Sponsored By: Credant_200x51 Tenable Pgp_logo Zecurion
Permission is granted to use this database in non-profit works and research. Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation for commercial interests requires authorization and licensing arrangements. For more information, please e-mail curators@datalossdb.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2010, Open Security Foundation, All Rights Reserved.