Supply chain β›“ Supply Chain

The Clark County School District Third-Party Breach (October 2019)

πŸ“… 2019-10-01 🏒 Pearson Clinical Assessment (AIMSweb)
Primary Source β†—

Incident Details

CCSD says students, staff affected by third party data breach. The Clark County School District says a vendor it uses has experienced a data security incident. The school district, in a press release, notes the incident involves several other school districts and involves an older version of a Pearson educational program. 559,8487 students who were enrolled between 2008 and 2019 along with a “smaller number” of staff members who were employed in the time period are also affected. LAS VEGAS (KSNV) β€” The Clark County School District says a vendor it uses has experienced a data security incident. Educational software provider Pearson is offering free access to credit monitoring services for individuals who were affected by the beach. Third-party company: Pearson Clinical Assessment (AIMSweb).

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Pearson Clinical Assessment (AIMSweb)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2019-10-01 Breach occurred
  2. 2019-08-02 Publicly disclosed