Yale warns 43,000 about 10-month-long data breach

22.08.2011

In a statement to Computerworld, Yale officials make no mention of how the data was compromised. BUt the school said it has "secured" the file and Google has confirmed that its search engine no longer stores any information from it.

The statement doesn't say how Yale discovered the breach, nor whether any of the data available via Google was accessed by anyone. Peters told the campus publication that the file and the directory in which the exposed information was stored had innocuous sounding names that are unlikely to have tipped off others about the contents.

This is the second publicly known breach in the last two months involving the inadvertent exposure of sensitive data on the Web. In June, Southern California Medical-Legal Consultants Inc. (SCMLC) said that the names and Social numbers of about 300,000 people who had filed for California workers compensation had been potentially compromised. That breach resulted when an internal server on which the data was stored became exposed to web searches.

SCMLC learned of the breach from security firm Identity Finder. In a statement, Identity Finder said that its security researchers had uncovered 3,875 uncompressed files containing several gigabytes of personal data on an SCMLC server that was exposed to the Web.

"The files were neither encrypted nor password-protected and some were cached by at least one major search engine," Identity Finder said. The company subsequently worked with Google to clear search engine caches, a spokesman for the company said. As of today, Google caches are clear of sensitive personal information from SCLMC, the spokesman said.