Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Report: Princeton Review publishes sensitive data online

By Joan Goodchild , CSO , 08/19/2008
  • Share/Email
  • Comment
  • Print

The Princeton Review is the latest company hit with a data breach that is making headlines. The New York-based educational service and test preparation provider inadvertently exposed files on at least 100,000 students in Sarasota, Florida and Fairfax County, Virginia through its Web site. News of the breach was made public Tuesday morning by a report in the New York Times.

Files were exposed after the company switched Internet service providers earlier this year. The sensitive information, which included personal data such as names, birth dates, ethnicities and learning disabilities, along with test performance, were easily accessed through a simple Web search and were available for at least seven weeks, according to the report. None of the information was password protected and was intended only to be viewed by Princeton Review authors.

Princeton Review officials told The NYT that access to the information was immediately shut down as soon as the company was informed about the problem.

This brings up two big questions," said Graham Cluley, a senior technology consultant with IT security and control firm Sophos. "Are companies doing enough to protect their data and also do companies really need to be keeping all of this kind of data?"

The flaw was discovered by a competing test preparation firm. The competitor contacted the NYT with the story, according to Cluley, who said the play-out points to the high stakes now involved with a data breach.

If companies haven't heard this before, its a huge reminder that security is important not just for your customers, but for your reputation.

While the publishing of birth dates may not seem like a massive leak, Cluley said the information is a good stepping stone for someone attempting to steal an identity.

This is the second time in a month a public breach has involved birth dates. A glitch in a test version of social networking site Facebook inadvertently exposed the birthdays of its 80 million members last month. The bug was discovered by Cluley who was checking out Facebook's new design when he noticed that the birth dates of some of his privacy-obsessed acquaintances were popping up when they should have been hidden.

"The fact that the people affected by this latest breach were children I think adds to the general background radiation about security, or lack thereof, of peoples' data on the Web," said Cluley.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (1)
Login
Forgot your account info?

Data BreachBy Anonymous on August 20, 2008, 9:33 amI'll bet that neither Princeton Review or the two school systems that are involved plan to contact the 100K people whose personal info was released... This kind...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed