The Arrowhead Regional Computing Consortium, a Minnesota-based educational advisory group, said that the data breach it suffered last year compromised the sensitive personal information of more than 65,000 people.
Arrowhead Regional Computing Consortium (ARCC) provides payroll processing, finance, student information and technological services to various schools in the Minnesota school district. ARCC says its mission is to provide services, deliver training, and promote innovation to support regional school districts.
In a recent data security incident notice filed with the Office of the Attorney General of Maine, ARCC
said that on February 6 last year, it detected unauthorised activity in its internal network and immediately launched an investigation with assistance from third party cyber security experts to understand the nature and scope of the incident.
The investigation, which was concluded on December 7, revealed that the sensitive personal information of individuals associated with ARCC was compromised during the incident. The compromised information included victims’ full names, Social Security Numbers, health insurance information, and medical information.
The consortium’s filing with the regulator also revealed that at least 65,010 individuals were affected by the data security incident.
"Please accept our apologies that this incident occurred. ARCC is committed to maintaining the privacy of personal information in our possession and have taken many precautions to safeguard it. We continually evaluate and modify our
practices and internal controls to enhance the security and privacy of your personal information," the consortium wrote in a letter to affected customers.
ARCC says it is not aware of any reports about identity fraud or improper use of any compromised information, but the possibility of malicious actors exploiting the stolen information cannot be ruled out.
It has urged all impacted individuals to take steps and protect themselves against identity fraud by placing a fraud alert and security freeze on their credit files, obtaining free credit reports regularly, and remaining vigilant in reviewing their financial account statements.
ARCC is also providing a year of complimentary credit monitoring and identity theft protection services through IDX to all the individuals affected by the incident.
On April 11, the notorious LockBit ransomware group claimed responsibility for the cyber attack on ARCC and listed the consortium as a victim on its data leak site. The group gave ARCC a deadline of April 18 to pay a ransom, failing which the stolen data will be released to the public.