Supply chain ⛓ Supply Chain

Michigan State University Third-Party Breach (April 2020)

📅 2020-04-01 🏢 Volusion
Primary Source ↗

Incident Details

MSU says data breach of third party vendor impacts hundreds. Michigan State University said it has been informed by E-commerce vendor Volusion, which provides online payment processing to thousands across the country, of a nationwide data breach. The university said it was informed that the data breach “impacted less than 300 customers who processed credit card payments for good through shop.msu.edu between Sept. 7, 2019 and Oct. 8, 2019.”. “While there was no breach to Michigan State University’s networks or systems, this breach of a third-party vendor is concerning and compels us to do what we can to help those impacted by sharing this important information,” said MSU Chief Information Officer Melissa Woo. “We know that the best tool in protecting yourself from identity theft and preserving your personal information is accurate information and swift action.”. Third-party company: Volusion.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Volusion
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-04-01 Breach occurred
  2. 2020-04-21 Publicly disclosed