{"id":24218,"date":"2023-09-05T09:00:33","date_gmt":"2023-09-05T16:00:33","guid":{"rendered":"https:\/\/www.nexusnewspaper.com\/?p=24218"},"modified":"2023-08-28T15:36:08","modified_gmt":"2023-08-28T22:36:08","slug":"camosun-college-students-impacted-by-security-breach","status":"publish","type":"post","link":"https:\/\/www.nexusnewspaper.com\/newsite\/2023\/09\/05\/camosun-college-students-impacted-by-security-breach\/","title":{"rendered":"Camosun College students impacted by security breach"},"content":{"rendered":"<p>Some Camosun College students had their student ID, name, and date of birth accessed in a data breach incident that happened earlier this year.<\/p>\n<p>On March 10, 2023, Gallivan\u2014a partner organization to the Camosun College Student Society (CCSS) that provides post-secondary organizations with health and dental plans\u2014was notified about the breach. The data breach happened with file transfer software GoAnywhere MFT, developed by cybersecurity company Fortra; the vulnerability that led to the breach has impacted over 100 organizations worldwide.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<figure id=\"attachment_24219\" aria-describedby=\"caption-attachment-24219\" style=\"width: 300px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/www.nexusnewspaper.com\/newsite\/wp-content\/uploads\/2023\/08\/PXL_20230818_212449925.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-24219\" src=\"https:\/\/www.nexusnewspaper.com\/newsite\/wp-content\/uploads\/2023\/08\/PXL_20230818_212449925-300x226.jpg\" alt=\"\" width=\"300\" height=\"226\" srcset=\"https:\/\/www.nexusnewspaper.com\/newsite\/wp-content\/uploads\/2023\/08\/PXL_20230818_212449925-300x226.jpg 300w, https:\/\/www.nexusnewspaper.com\/newsite\/wp-content\/uploads\/2023\/08\/PXL_20230818_212449925-272x204.jpg 272w, https:\/\/www.nexusnewspaper.com\/newsite\/wp-content\/uploads\/2023\/08\/PXL_20230818_212449925.jpg 700w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><figcaption id=\"caption-attachment-24219\" class=\"wp-caption-text\">Some Camosun College students received this email from Gallivan on July 19 informing them about a data breach (photo by Greg Pratt\/<em>Nexus<\/em>).<\/figcaption><\/figure>\n<p>An email was sent to the impacted students on July 19 from the CCSS on behalf of Gallivan. In the email, Gallivan states that the breach was reported to the Office of the Privacy Commissioner of Canada and provincial privacy authorities. (As of press time, Gallivan has not responded to requests for an interview with <i>Nexus<\/i>.)<\/p>\n<p>A credit monitoring service, MyTrueIdentity, is being offered to impacted students free of charge for a 12-month period. Students who have minimal or no credit history, however, aren\u2019t eligible for credit monitoring services; instead, a darkweb monitoring service may be available to them.<span class=\"Apple-converted-space\">\u00a0<\/span><\/p>\n<p>CCSS executive director Michel Turcotte says that students who were contacted regarding the breach shouldn\u2019t panic due to the limited amount of information that was compromised, and he says there\u2019s no evidence that the stolen data has been used.<\/p>\n<p>\u201cFirst, I\u2019d like to say that any student that was impacted by the breach&#8230; knows about it because they were directly communicated to,\u201d says Turcotte. \u201cIf a student hasn\u2019t been notified, we don\u2019t want to create some sense of panic, because they were not impacted by the breach&#8230; We know exactly who was, you know, potentially impacted. But that said, the data breach was as a result of a third-party software that was used by one of the partners which we work with to provide health and dental insurance to the students. And, we have to transfer some data so that the students can be enrolled with Canada Life [Insurance], and that special file transfer software was potentially impacted by a data breach.\u201d<\/p>\n<p>Turcotte says that the breach might have more to do with the persistence of hackers than the security of the GoAnywhere software that was compromised.<\/p>\n<p>\u201cThe file transfer program that was impacted was considered to be one of the most secure in the industry by a major company whose business is providing internet security,\u201d says Turcotte. \u201cI mean, it\u2019s a tricky world out there in terms of cybersecurity. So, I don\u2019t know what more could have been done under the circumstances, because in order to do business and provide services, information of some sort needs to be transferred. And you can do everything you can, as was done in this case, to protect that data but sometimes if groups of hackers or nation-states or that sort of stuff devote enough energy, nowadays, you can brute force anything.\u201d<\/p>\n<p>To protect students, a new file transfer program is now being used; according to Turcotte, it\u2019s also considered to be one of the best in the industry.<\/p>\n<p>\u201cIt\u2019s a scary world out there in terms of privacy and internet security,\u201d he says. \u201cThe whole industry might be working towards finding better ways at securing data in general, or the public will have different expectations about privacy and those sorts of things. I\u2019m not sure what\u2019s going to happen, but a different program is now being used to transfer that information, and we hope it\u2019s secure&#8230; It was selected by one of our partners, but it\u2019s supposed to be also one of the best in the industry. There\u2019s been a lot of work put into trying to make sure that this doesn\u2019t happen again.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some Camosun College students had their student ID, name, and date of birth accessed in a data breach incident that happened earlier this year. On March 10, 2023, Gallivan\u2014a partner organization to the Camosun College Student Society (CCSS) that provides post-secondary organizations with health and dental plans\u2014was notified about the breach. The data breach happened [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":24219,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[13,294],"tags":[],"class_list":["post-24218","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-september-5-2023"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/posts\/24218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/comments?post=24218"}],"version-history":[{"count":1,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/posts\/24218\/revisions"}],"predecessor-version":[{"id":24220,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/posts\/24218\/revisions\/24220"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/media\/24219"}],"wp:attachment":[{"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/media?parent=24218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/categories?post=24218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nexusnewspaper.com\/newsite\/wp-json\/wp\/v2\/tags?post=24218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}