The New York City Department of Education has joined the growing list of organizations affected by the widespread hack of MOVEit file transfer software. In an email sent to parents on Sunday, the agency revealed that the private data of approximately 45,000 students had been compromised, including sensitive details such as social security numbers and birth dates. The personal information of staff members was also accessed, although the exact number of affected teachers and personnel remains undisclosed.

Emphasizing the utmost importance of safeguarding the personal information and data of students and staff, the Education Department assured that it is diligently working to determine the extent of the confidential information that was exposed and the specific impact on each affected individual. Once the assessment is complete, the department will initiate notifications to individuals whose confidential information was compromised. Additionally, affected individuals will be offered access to an identity monitoring service.

The MOVEit hack, which occurred in early June, has affected numerous organizations, and the New York City Department of Education is the latest to disclose the breach. The cyberattack was claimed by Clop, a ransomware gang with suspected pro-Russian ties. Exploiting a zero-day vulnerability in the enterprise file transfer software, the group successfully breached the servers of "hundreds of companies," including the largest pension fund in the United States.

While the scale of the data breach at the New York City Department of Education may be relatively small compared to other victims, it is notable due to the inclusion of personal information belonging to minors. In an interview with Bleeping Computer, the Clop gang stated its intention to erase any data obtained from governments, the military, and children's hospitals. However, it remains uncertain whether the group considers student data to fall within the latter category.

The Education Department is actively working to address the breach and mitigate its impact on students and staff. The incident serves as a reminder of the increasing threat posed by cyberattacks and the critical need for organizations to strengthen their security measures to safeguard sensitive information from unauthorized access.

