OneClass

NJCCIC Data Breach Notification

Original Release Date: 7/3/2020

Summary

Researchers at vpnMentor discovered an unsecured Elasticsearch database belonging to OneClass exposing 27 GB of user data. OneClass is an online learning platform used by colleges nationwide in which instructors can post study guides, and provide learning materials and tutoring to students as young as age thirteen. Exposed data includes full names, email addresses, phone numbers, schools and universities attended, course enrollment, and account details totaling approximately 8.9 million records affecting over one million users. The database was secured within 24 hours of disclosure; though at the time of this writing, it is unknown who else may have accessed the exposed information. Much of the breached data could be used by cyber-criminals in targeted phishing campaigns against account holders, including minors.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.