{"id":6194,"date":"2021-10-15T10:00:00","date_gmt":"2021-10-15T15:00:00","guid":{"rendered":"https:\/\/hoorfarlaw.com\/blog\/?p=6194"},"modified":"2021-10-15T12:17:45","modified_gmt":"2021-10-15T17:17:45","slug":"missouri-teachers-social-security-numbers-at-risk-on-state-agencys-website","status":"publish","type":"post","link":"https:\/\/hoorfarlaw.com\/blog\/?p=6194","title":{"rendered":"Missouri teachers\u2019 Social Security numbers at risk on state agency\u2019s website"},"content":{"rendered":"\n<p>The Social Security numbers of school teachers, administrators and counselors across Missouri were vulnerable to public exposure due to flaws on a website maintained by the state\u2019s Department of Elementary and Secondary Education.<\/p>\n\n\n\n<p>The Post-Dispatch discovered the vulnerability in a web application that allowed the public to search teacher certifications and credentials. The department removed the affected pages from its website Tuesday after being notified of the problem by the Post-Dispatch.<\/p>\n\n\n\n<p>Based on state pay records and other data, more than 100,000 Social Security numbers were vulnerable.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><a href=\"https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-1024x576.jpg\" alt=\"\" class=\"wp-image-6195\" width=\"257\" height=\"144\" srcset=\"https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-1024x576.jpg 1024w, https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-300x169.jpg 300w, https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-768x432.jpg 768w, https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-1536x864.jpg 1536w, https:\/\/hoorfarlaw.com\/blog\/wp-content\/uploads\/2021\/10\/social-security-2048x1152.jpg 2048w\" sizes=\"auto, (max-width: 257px) 100vw, 257px\" \/><\/a><\/figure><\/div>\n\n\n\n<p>The newspaper delayed publishing this report to give the department time to take steps to protect teachers\u2019 private information, and to allow the state to ensure no other agencies\u2019 web applications contained similar vulnerabilities.<\/p>\n\n\n\n<p>It wasn\u2019t immediately clear how long the Social Security numbers and other sensitive information had been vulnerable on the DESE website, nor was it known if anyone had exploited the flaw.<\/p>\n\n\n\n<p>Though no private information was clearly visible nor searchable on any of the web pages, the newspaper found that teachers\u2019 Social Security numbers were contained in the HTML source code of the pages involved.<\/p>\n\n\n\n<p>The 2015 audit found that DESE was unnecessarily storing students\u2019 Social Security numbers and other personally identifiable information in its Missouri Student Information System. The audit urged the department to stop that practice and to create a comprehensive policy for responding to data breaches, among other recommendations. The department complied, but clearly at least one other system contained an undetected vulnerability.<\/p>\n\n\n\n<p>In the letter to teachers, Education Commissioner Margie Vandeven said \u201can individual took the records of at least three educators, unencrypted the source code from the webpage, and viewed the social security number (SSN) of those specific educators.\u201d<\/p>\n\n\n\n<p>In reality, the Post-Dispatch discovered the vulnerability and confirmed that the nine-digit numbers were indeed Social Security numbers. The paper then told the department that it had confirmed the vulnerability with three educators and a cybersecurity expert.<\/p>\n\n\n\n<p>But in the press release, DESE called the person who discovered the vulnerability a \u201chacker\u201d and said that individual \u201ctook the records of at least three educators\u201d \u2014 instead of acknowledging that more than 100,000 numbers had been at risk, and that they had been available to anyone through DESE\u2019s own search engine.<\/p>\n\n\n\n<p>\u201cFor those educators determined to be impacted by this vulnerability, the state will make every effort to contact you directly as soon as possible to share information about the next steps,\u201d Vandeven said in her letter.<\/p>\n\n\n\n<p>Post-Dispatch attorney Joseph Martineau, of Lewis Rice, responded to DESE\u2019s statements late Wednesday:<\/p>\n\n\n\n<p>\u201cThe reporter did the responsible thing by reporting his findings to DESE so that the state could act to prevent disclosure and misuse,\u201d Martineau said in a written statement. \u201cA hacker is someone who subverts computer security with malicious or criminal intent. Here, there was no breach of any firewall or security and certainly no malicious intent.<\/p>\n\n\n\n<p>\u201cFor DESE to deflect its failures by referring to this as \u2018hacking\u2019 is unfounded. Thankfully, these failures were discovered.\u201d<\/p>\n\n\n\n<h4 class=\"has-medium-font-size wp-block-heading\"><strong>What teachers can do<\/strong><\/h4>\n\n\n\n<p>Shaji Khan, a cybersecurity professor at the University of Missouri-St. Louis, recommended that Missouri teachers request a&nbsp;<a href=\"https:\/\/www.ftc.gov\/faq\/consumer-protection\/get-my-free-credit-report\" target=\"_blank\" rel=\"noreferrer noopener\">free credit report<\/a>&nbsp;from the three major credit bureaus \u2014 Equifax, Transunion and Experian \u2014 and monitor them carefully. Teachers should place a credit freeze with the bureaus if they notice suspicious activity, he said.<\/p>\n\n\n\n<p><strong>People who believe their&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/ago.mo.gov\/civil-division\/consumer\/identity-theft-data-security\/identity-theft\" target=\"_blank\">identity has been stolen<\/a>&nbsp;may report it to the Federal Trade Commission at&nbsp;<a rel=\"noreferrer noopener\" href=\"http:\/\/www.identitytheft.gov\/\" target=\"_blank\">www.identitytheft.gov<\/a>.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Social Security numbers of school teachers, administrators and counselors across Missouri were vulnerable to public exposure due to flaws on a website maintained by the state\u2019s Department of Elementary and Secondary Education. The Post-Dispatch discovered the vulnerability in a &hellip; <a href=\"https:\/\/hoorfarlaw.com\/blog\/?p=6194\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-6194","post","type-post","status-publish","format-standard","hentry","category-general"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6194"}],"version-history":[{"count":2,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6194\/revisions"}],"predecessor-version":[{"id":6197,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6194\/revisions\/6197"}],"wp:attachment":[{"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hoorfarlaw.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}