SmarterSelect exposed personal data of students |
Education software company SmarterSelect, which provides a platform for managing the application process for scholarships, exposed the personal data of thousands of applicants because of a misconfigured Google Cloud Storage bucket. Cybersecurity firm UpGuard found that the data included documents such as academic transcripts, resumes and invoices for approximately 1.2 million applications to funding programs, dated from November 2020 to September 21 2021. One folder hosted on the public bucket hosted 23,000 spreadsheets and 8,000 ZIP files, which contained contact information like name, email address and phone number, as well as much more probing details such as parents’ education and income, the students’ performance at school, student photos where required for application, and financial documents such as Free Application for Federal Student Aid (FAFSA) forms that, in some cases, included full Social Security numbers, proof of COVID-19 vaccinations and descriptions of hardships.