Third-party data breach impacts WSU community members
Our take
In recent weeks, the Washington State University (WSU) community has been alerted to a significant cybersecurity incident involving the MOVEit Transfer application, a widely used file-sharing service that has caught the attention of news outlets and cybersecurity analysts alike. Although WSU does not utilize this software, the repercussions of the breach extend into our community, as third-party service providers have notified the university that personally identifiable information of some members may have been compromised. This incident underscores the pervasive nature of cybersecurity threats and raises pressing concerns about the safety and privacy of our information in an increasingly digital world. In a similar vein, the recent Court Rules Texas State Must Reinstate Prof Fired for Israel-Palestine Talk and Kentucky State University Students, Alumni Sue to Block New State Law articles reflect a broader theme of institutional accountability and the need for transparency in higher education, resonating with WSU’s ongoing commitment to protect its community members.
The impact of such breaches can be far-reaching, affecting not just individual privacy but also the overall trust that students and staff place in the university and its partners. As digital natives, many students at WSU rely heavily on online platforms for everything from coursework to personal communication. When such platforms fail to safeguard our information, it creates a ripple effect of anxiety and uncertainty. At a time when students are already grappling with the pressures of academic life, the added concern about the security of their personal data can feel overwhelming. The incident serves as a reminder that even institutions that do not directly engage with compromised software can find themselves enmeshed in the fallout of breaches, highlighting the interconnectedness of our digital lives.
Moreover, this incident raises questions about the measures that WSU and its partners are taking to ensure such breaches do not occur in the first place. Are adequate safeguards in place to protect student data? How transparent are the university’s third-party service providers about their own cybersecurity practices? As students, it’s essential for us to advocate for our own data security and demand clarity from the institutions we trust. WSU's response to this breach will be closely watched, as it will reflect not only the university's commitment to its community but also its readiness to handle the complexities of modern technology. The importance of fostering a culture of transparency and mutual accountability cannot be overstated, as it is vital for maintaining trust between the university and its students.
As we look toward the future, the WSU community must remain vigilant and proactive in safeguarding our digital identities. This incident serves as a wake-up call for everyone involved in higher education—students, faculty, and administration alike. Will WSU take this opportunity to bolster its cybersecurity measures and engage more deeply with its community about data privacy? How can we collectively enhance our understanding of cybersecurity threats and protect ourselves against them? It will be interesting to see how WSU navigates this situation and what steps will be taken to ensure that our information remains secure in the face of evolving cyber threats. The conversation surrounding cybersecurity is only beginning, and as members of the WSU community, we must stay engaged and informed.
Updated July 24, 2023
According to national news media reports, many businesses and organizations worldwide have been impacted by a cybersecurity incident related to a widely used filesharing application known as MOVEit Transfer.
While Washington State University does not use the MOVEit software, WSU has received notifications from third-party service providers that personally identifiable information from some current and prospective WSU students and employees may have been exposed.
The third-party service providers who have contacted WSU include the National Student Clearinghouse (NSC), the Teachers Insurance and Annuity Association (TIAA), and UnitedHealthcare.
National Student Clearinghouse
The National Student Clearinghouse is a nonprofit organization that provides educational reporting, data exchange, and verification services to more than 3,600 colleges and universities nationwide. WSU works with the clearinghouse for a variety of purposes including enrollment and degree verification services and student loan reporting requirements. Data provided to the National Student Clearinghouse includes personally identifiable information and education records.
The National Student Clearinghouse has posted details about this incident on its website.
Teachers Insurance and Annuity Association (TIAA)
TIAA is a financial organization that offers investment and insurance services to employees working in the academic, research, medical, governmental, and cultural fields. Washington State University provides names, addresses, dates of birth, and social security numbers for those employees who choose to participate in TIAA services. The data transferred from WSU to TIAA was not compromised. However, TIAA has indicated that Pension Benefit Information, LLC, an outside vendor it shares information with, has been impacted.
UnitedHealthcare
UnitedHealthcare makes health insurance plans available to college students across the country, including at Washington State University. UnitedHealthcare notified the university that personally identifiable information, as well as claims information, for some of its WSU student customers was accessed during a MOVEit Transfer cyberattack in June.
UnitedHealthcare has established a dedicated, toll-free telephone number (1-866-341-4262) that its policy holders can call for additional information regarding the MOVEit Transfer breach.
What steps can I take to protect myself?
The Federal Trade Commission offers recommendations if you think your personal information has been compromised. These include:
- Closely monitor your credit reports.
- You can obtain a free copy of your credit report from each of the three major credit reporting agencies; Equifax, Experian, and TransUnion.
- Place a fraud alert on your accounts.
- A fraud alert tells creditors to contact you before opening any new accounts or before making changes to existing accounts. You can place a fraud alert by contacting one of the three credit reporting agencies. A fraud alert at one of the agencies will automatically notify the other two services.
- Freeze your credit at each of the three major credit reporting agencies.
- If you believe you are the victim of identity theft, file a police report and notify the Federal Trade Commission at www.identitytheft.gov.
- Block electronic access to your Social Security information.
- Contact the Social Security Administration at 1-800-772-1213 to block electronic access. This will prevent anyone from being able to see or change your personal information on the internet or by the administration’s automated telephone service.
Moving forward
Washington State University expects that the National Student Clearinghouse, UnitedHealthcare, and Pension Benefit Information, LLC, a vendor for the Teachers Insurance and Annuity Association, will contact impacted individuals directly with additional details where required by law.
WSU will continue to update this webpage as new information becomes available from the service providers.
Read on the original site
Open the publisher's page for the full experience