Chitchat MOE School Gets Hacked! Was It Done By Russians, Chinks, North Korea or Oppies?

JohnTan

Alfrescian (InfP)
Generous Asset
Joined
Oct 30, 2014
Messages
36,768
Points
113
000831973.jpg


SINGAPORE - The NRIC numbers of hundreds of students at Xinmin Secondary School were leaked in the second known data breach by a Ministry of Education (MOE) school since March 2015.

The information was posted a few months ago on file-sharing website pastebin.com, but The Straits Times understands that it has since been taken off the site and a police report has been made.

Xinmin Secondary School's vice-principal Tan Kuo Cheang confirmed with ST on Saturday (Nov 18) that the school was alerted "to a data breach involving a leak of our students' personal information on pastebin.com" on Sept 28.

The school immediately contacted the website, asking for the information to be removed, and also filed a police report.

It then contacted its students to alert them of the leak and to share cyber security measures that they could take, such as avoiding using NRIC numbers as passwords.

Mr Tan declined to comment further as investigations are ongoing.


When contacted, a spokesman for MOE said: "In line with government IT security policies, MOE has stepped up efforts to work with schools and ensure that their security measures continue to be effective."

She added: "As investigations are ongoing, we are unable to share more."

In March 2015, the personal data of more than 1,900 pupils from Henry Park Primary School were exposed.

An Excel spreadsheet containing the children's particulars was mistakenly sent out to about 1,200 parents as part of an update about a school event.
The file contained the names and birth certificate numbers of all 1,900 pupils in the school, and the names, phone numbers and e-mail addresses of their parents.

MOE schools such as Xinmin Secondary and Henry Park are exempted from the Personal Data Protection Act, fully enforced from July 2014. The Act requires organisations to take "reasonable measures" to protect personal data in their possession.

Instead, MOE schools are governed by public-sector rules, which have not been made public.

Technology lawyer Bryan Tan of Pinsent Masons MPillay said: "The Government said that its standards are more stringent than those that govern the private sector. But when a public incident like this happens, we can assess whether the first statement is true."

Lawyer Mr Koh Chia Ling from law firm OC Queen Street said that the students have no recourse. "Even if they do, it might be difficult for them to show any loss suffered from negligence or breach of contract," he said.

http://www.straitstimes.com/tech/xi...-numbers-leaked-on-file-sharing-site-pastebin
 
Dafug?! How did this happen?

You tell me. You are an oppie.

I recommend that the police bring in oppies like Low, Chee, and Chiam in for questioning. We will get the truth out of them after a few rounds of electrocution to their tits and privates
 
I'm not an expert in this field and I'm not even sure if oppies have such capabilities. You can try asking Prof Ben if he has any clues.

Some disgruntled teachers or we call them 'educators' or "volunteers' working for MOE..with a grudge, dumped the data into the internet.
 
Some disgruntled teachers or we call them 'educators' or "volunteers' working for MOE..with a grudge, dumped the data into the internet.

Hmm... sounds plausible but how easy is it to lay hands on student IC numbers? Looks like I need to sqeeze more info tonight... Busy night.
 
Hmm... sounds plausible but how easy is it to lay hands on student IC numbers? Looks like I need to sqeeze more info tonight... Busy night.

They have underpaid staff, many of which are just graduated or looking for work; & passing time, working in the school Admin. Offices & even MOE. They are part-time or even contract staff, little wonder, that this breach of privacy didn't occur early.

If you child is involved in school activities etc...they will have list of the class, the children's name, parents name, contact numbers, addresses, job description & ID...so, it is not impossible to obtain info...get it!
 
will education minister say this is a case of digital amnesia?
 
Back
Top