Jump to content

Recommended Posts

Posted
A school that I work for has just called me in a fluster. Apparently they use a Gmail account to email parents and sent out a newsletter this morning. They have just been contacted by a parent to say a second email went out with all their (the schools) pupil information from what looks like SIMs. No one in the school sent the email, it's gone to all parents! Massive breach of data. Is this possible? I didn't even know they had a Gmail account, they use rm easymail for everything else. Can anyone shed any light on what may have happened and how to stop it happening again. I have no knowledge on this :/
Posted
So two things have been "hacked" the gmail account and someone has managed to get in to SIMS and run a report and then email out? have you seen a copy of the email and the data that went out?
Posted

The obvious thing would be for said parent to forward the e-mail back to you for inspection.

 

Also, if they did a bulk e-mail, did they BCC everyone? It's a mistake I've seen before!

Posted

Until you can ascertain what has happened these are the steps I would take.

 

Do they have access to SIMS remotely? disable it!

 

Change the passwords of all user and admin accounts, change the gmail password. If you feel the network has been compromised unplug it from the internet

 

Get a copy of the email.

  • Thanks 1
Posted
I've just spoken to the school again. They have the techie people from their education authority checking it out, their admin machines are support by them. They can't even see where the email was sent from so have asked one of the parents to send it back to them. The only remote access is from the authority's support team. Thank you all for your advice
Posted

Depending on the data you might need to inform the ICO.

 

We had something like this, in the end it turned out to be someone in the office accidentally sending an email for our Local authority to an all parents email group and then to make everything worse trying to hide they had done it.

  • Thanks 3
Posted
2 factor authentication should be switched on for that Gmail account. Either set it up with a PAYG mobile in the office or buy a few U2F USB security keys for the staff that want to use it.
Posted
Either set it up with a PAYG mobile in the office or buy a few U2F USB security keys for the staff that want to use it.

The U2F keys or a TOTP app would be the best option. SMS (even with 2FA) should be avoided.

 

Adding a phone number to your Google account can make it LESS secure

 

In order to secure your Google account, you should really enable two-factor auth, and use either a U2F/FIDO device, or a TOTP app like Google Authenticator, Duo, or Authy. If, for whatever reason, you don’t have two-factor authentication enabled, I would strongly recommend not adding a backup phone to your account as it could ironically reduce the security of your account. SMS-based two-factor auth is risky also: if an attacker can convince your telco to turn over your phone number to him/her, he/she will have access to your two-factor codes as well.

 

US standards lab says SMS is no good for authentication

 

America's National Institute for Standards and Technology has advised abandonment of SMS-based two-factor authentication.
Posted
I'm afraid to say (but also relieved :/) that the issue is now believed to have been human error. Some very hard lessons have been learned. Once again thank you all for your advice and support.
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...