Cazale Posted December 18, 2020 Posted December 18, 2020 According to this blog.. ParentPay have been a victim of Sunburst! https://blog.prevasio.com/2020/12/sunburst-backdoor-part-ii-dga-list-of.html Is anyone on here from ParentPay? Can you confirm/deny? Has there been any data loss? 2
3s-gtech Posted December 18, 2020 Posted December 18, 2020 Parentpay.local rather than .com - so their internal domain. That could be good (relatively) or very very bad.
Cazale Posted December 18, 2020 Author Posted December 18, 2020 Parentpay.local rather than .com - so their internal domain. That could be good (relatively) or very very bad. I suspect bad! (but very much hope I'm wrong)
coolhands Posted December 22, 2020 Posted December 22, 2020 well on the back of this I just went to change my password to new random password - they appear to have blocked it! So can't change my own password! That's nice going, stuck with their insecure system!
willtech Posted December 22, 2020 Posted December 22, 2020 Got a call logged to ask them and no reply at all to the question.
coolhands Posted December 22, 2020 Posted December 22, 2020 As I happen to have a private parent account (for my children) I just tested - I was able to change my password. So it's just the full on school admin password that can't be changed which is a) odd and b) annoying. To be honest I find their whole system awful anyway. Having to upload staff manually through MISsync?, woeful instructions on anything you try to find out etc etc 2
sigma Posted December 22, 2020 Posted December 22, 2020 I really think they should have made a statement by now, even if it was just to confirm they are investigating. The current nil response and nothing whatsoever on the website provides zero confidence.
willtech Posted December 22, 2020 Posted December 22, 2020 (edited) I have been told my ticket is with security I await to hear. Edited December 22, 2020 by willtech
Cazale Posted December 22, 2020 Author Posted December 22, 2020 I asked on Twitter the same time as I posed this thread, no reply. 1
msi_school Posted December 22, 2020 Posted December 22, 2020 (edited) I am speaking to them now, they assure me that there is a statement on the site the link here https://www.parentpay.com/schools/ then scroll all the way to the bottom and it is in the news is not showing it to me. I am also not receiving emails that they are claiming to have sent me. Edit I have just received the emails, their statement. A statement from our IT Security team December 22, 2020 As is being widely reported, SolarWinds recently suffered a security breach, potentially impacting tens of thousands of SolarWinds customers worldwide. As a user of SolarWinds, as soon as ParentPay were made aware of the breach we isolated our systems and launched an immediate and thorough investigation. We have found no evidence to suggest ParentPay customer or partner data has been breached or compromised in any way. Having analysed our detailed historic logs (available from throughout the full timeframe), and conducted technical forensics analysis, we have found no indications that those responsible sought to further access ParentPay systems. All of our SolarWinds services and systems have been shut down and permanently removed from the ParentPay network. Safeguarding customer and partner data is our top priority and all such information is given the utmost protection. We remain confident that such data was safely isolated from this incident. Our dedicated IT security team continues to monitor the situation and are sharing any supporting information with the wider security community. Edited December 22, 2020 by msi_school 3
willtech Posted December 22, 2020 Posted December 22, 2020 (edited) I am speaking to them now, they assure me that there is a statement on the site the link here https://www.parentpay.com/schools/ then scroll all the way to the bottom and it is in the news is not showing it to me. I am also not receiving emails that they are claiming to have sent me. Edit I have just received the emails, their statement. A statement from our IT Security team December 22, 2020 As is being widely reported, SolarWinds recently suffered a security breach, potentially impacting tens of thousands of SolarWinds customers worldwide. As a user of SolarWinds, as soon as ParentPay were made aware of the breach we isolated our systems and launched an immediate and thorough investigation. We have found no evidence to suggest ParentPay customer or partner data has been breached or compromised in any way. Having analysed our detailed historic logs (available from throughout the full timeframe), and conducted technical forensics analysis, we have found no indications that those responsible sought to further access ParentPay systems. All of our SolarWinds services and systems have been shut down and permanently removed from the ParentPay network. Safeguarding customer and partner data is our top priority and all such information is given the utmost protection. We remain confident that such data was safely isolated from this incident. Our dedicated IT security team continues to monitor the situation and are sharing any supporting information with the wider security community. Hate to say that the statement has come quiet late with no feedback to customers to even say it was being looked at. And SIMS is going to fall under the Patent Pay Group, does not fill me with confidence. Would be a wonder when they actioned a lot of this. Edited December 22, 2020 by willtech 1
Cazale Posted December 22, 2020 Author Posted December 22, 2020 They just replied to me on Twitter with the same statement.
sigma Posted December 22, 2020 Posted December 22, 2020 They have replied with a link on Twitter. Looks the same: https://www.parentpay.com/a-statement-from-our-it-security-team/
DODICT Posted December 22, 2020 Posted December 22, 2020 Parent pay & sims what a combo - two outdated, relatively poor, products with significant customer bases. And the other thing in common IMHO - a poor attitude to their customers typified by responses like this - will be interesting to see if these two lumbering beasts can be turned round as there's a long way to go in terms of product and support. 4
synaesthesia Posted December 22, 2020 Posted December 22, 2020 I would have hoped for more transparency from such a company, and they should IMO be advising the changing of passwords regardless of whether or not they can confirm a data breach - yes that might make people assume the worst, however that little extra something would go a long way if they stumble on something a little later on down the line their initial investigations didn't pick up. 3
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now