Zhitong Finance App News, Australia's Chengfeng Higher Education (01752) issued an announcement. The Group has launched an investigation and appointed cybersecurity and forensic experts to assess the scope (investigation) of the suspected incident causing unauthorized access or disclosure of personal data (if any). Upon learning of the suspected incident, the Group also immediately took steps to identify possible unauthorized access points and take appropriate action to cut off the threat actor's connection and access rights to SMS.
According to the investigation results, an unauthorized third party (threatening actor) obtained access to the Company's Student Management System (SMS) through stolen credentials of an employee of the Group. Some personal data stored in SMS (such as identity data, contact information, admission data, etc.) may be accessed or disclosed without authorization. The Group estimates that approximately 24,934 people were affected by the suspected incident, including the Group's prospective students, students, graduates and employees who are or have been in Australia.
The Group has notified the Higher Education Quality and Standards Agency, the Australian Cybersecurity Centre, the Australian Government Department of Education, and the Australian Information Commissioner's Office.
The Group has notified affected persons to alert them to suspected incidents and possible disclosure of personal data as a result, and to provide relevant information on steps that can be taken to prevent potential misuse of personal data and to provide other support.
The Group has also implemented additional cybersecurity measures, including but not limited to resetting all employee account passwords, strengthening user authentication controls, implementing additional access restrictions and other surveillance measures aimed at detecting and preventing further unauthorized access. The Group is committed to protecting the personal data and data privacy of all students and employees through continuous strengthening of information system security protection measures to prevent similar incidents in the future.