Jump to content

Recommended Posts

Posted
Parentpay.local rather than .com - so their internal domain. That could be good (relatively) or very very bad.

I suspect bad! (but very much hope I'm wrong)

Posted
well on the back of this I just went to change my password to new random password - they appear to have blocked it! So can't change my own password! That's nice going, stuck with their insecure system!
Posted
As I happen to have a private parent account (for my children) I just tested - I was able to change my password. So it's just the full on school admin password that can't be changed which is a) odd and b) annoying. To be honest I find their whole system awful anyway. Having to upload staff manually through MISsync?, woeful instructions on anything you try to find out etc etc
  • Thanks 2
Posted
I really think they should have made a statement by now, even if it was just to confirm they are investigating. The current nil response and nothing whatsoever on the website provides zero confidence.
Posted (edited)

I am speaking to them now, they assure me that there is a statement on the site the link here https://www.parentpay.com/schools/ then scroll all the way to the bottom and it is in the news is not showing it to me.

 

I am also not receiving emails that they are claiming to have sent me.

 

Edit I have just received the emails, their statement.

 

A statement from our IT Security team



December 22, 2020

 

 

As is being widely reported, SolarWinds recently suffered a security breach, potentially impacting tens of thousands of SolarWinds customers worldwide.

As a user of SolarWinds, as soon as ParentPay were made aware of the breach we isolated our systems and launched an immediate and thorough investigation. We have found no evidence to suggest ParentPay customer or partner data has been breached or compromised in any way.

Having analysed our detailed historic logs (available from throughout the full timeframe), and conducted technical forensics analysis, we have found no indications that those responsible sought to further access ParentPay systems.

All of our SolarWinds services and systems have been shut down and permanently removed from the ParentPay network.

Safeguarding customer and partner data is our top priority and all such information is given the utmost protection. We remain confident that such data was safely isolated from this incident.

Our dedicated IT security team continues to monitor the situation and are sharing any supporting information with the wider security community.

Edited by msi_school
  • Thanks 3
Posted (edited)
I am speaking to them now, they assure me that there is a statement on the site the link here https://www.parentpay.com/schools/ then scroll all the way to the bottom and it is in the news is not showing it to me.

 

I am also not receiving emails that they are claiming to have sent me.

 

Edit I have just received the emails, their statement.

 

A statement from our IT Security team



December 22, 2020

 

 

As is being widely reported, SolarWinds recently suffered a security breach, potentially impacting tens of thousands of SolarWinds customers worldwide.

As a user of SolarWinds, as soon as ParentPay were made aware of the breach we isolated our systems and launched an immediate and thorough investigation. We have found no evidence to suggest ParentPay customer or partner data has been breached or compromised in any way.

Having analysed our detailed historic logs (available from throughout the full timeframe), and conducted technical forensics analysis, we have found no indications that those responsible sought to further access ParentPay systems.

All of our SolarWinds services and systems have been shut down and permanently removed from the ParentPay network.

Safeguarding customer and partner data is our top priority and all such information is given the utmost protection. We remain confident that such data was safely isolated from this incident.

Our dedicated IT security team continues to monitor the situation and are sharing any supporting information with the wider security community.

 

Hate to say that the statement has come quiet late with no feedback to customers to even say it was being looked at. And SIMS is going to fall under the Patent Pay Group, does not fill me with confidence.

 

Would be a wonder when they actioned a lot of this.

Edited by willtech
  • Thanks 1
Posted
Parent pay & sims what a combo - two outdated, relatively poor, products with significant customer bases. And the other thing in common IMHO - a poor attitude to their customers typified by responses like this - will be interesting to see if these two lumbering beasts can be turned round as there's a long way to go in terms of product and support.
  • Thanks 4
Posted
I would have hoped for more transparency from such a company, and they should IMO be advising the changing of passwords regardless of whether or not they can confirm a data breach - yes that might make people assume the worst, however that little extra something would go a long way if they stumble on something a little later on down the line their initial investigations didn't pick up.
  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...