Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

16,500 Student Loan Borrowers’ Information Exposed in Data Leak

by The Gurus
May 10, 2018
in Opinions & Analysis
Share on FacebookShare on Twitter

Data sent to a third-party vendor that was not authorized to receive it led to a data breach involving 16,500 people associated with student loans. The affected company is Access Group Education Lending, and the company became aware of the situation on March 23.

What Kind of Information Was Leaked?

The public doesn’t know the third-party vendor’s name, but the company is reportedly a student loan lender. That vendor got data containing student names, Social Security numbers and driver’s license numbers.

The Data Was Reportedly Destroyed

Nelnet, a company that processes data for Access Group, is the entity at fault for distributing that sensitive information to the unnamed outside vendor that shouldn’t have seen it.

Representatives from Nelnet say they don’t believe inappropriate data use occurred following the leak. Instead, they clarified the data traveled to the third-party vendor through an encrypted channel. Also, that company recognized the data transfer happened in error, then got rid of the information.

According to details released in SC Magazine, a relevant manager for the third-party vendor agreed to sign a sworn document confirming the destruction of the information with nothing retained.

A Year of Credit Monitoring Offered

When making a statement about the issue to the press, Access Group said the exposure of personal details was “limited.”

Even so, the company will provide a year of complimentary credit monitoring to affected parties who want to ensure the data leak won’t have negative repercussions. It notified those individuals in writing, and provided the same disclosure to the respective attorney generals at the state level.

A survey of more than 10,000 people around the world indicates a growing concern among consumers regarding data breaches. The results found 69 percent of respondents don’t think enterprises take data protection very seriously, and two-thirds feared becoming victims of future data breaches.

Preventing Similar Future Events

Access Group monitors its vendors and will continue to do so as a preventive measure against other data breaches. Furthermore, it will mandate written data transfer protocols for third-party companies and double-check the recipients before starting to send files.

Data leaks can happen externally, as well as from inside organizations. Efforts to reduce internal threats require carefully screening individuals who have access to a company’s data, issuing role-based permissions for sensitive information and establishing clear, documented employee expectations.

This breach did not originate within Access Group, but since the company works with third-party vendors, it must continue to treat those representatives as if they were employees working onsite.

Plus, tightening up internal security measures would be a smart move, since Access Group already attracted negative publicity with this breach and wouldn’t want to be associated with other problems.

The Three-Week Delay Before Notifying Customers

Access Group didn’t get word of the incident until five days after the mistaken data transfer. It has also emerged that the company did not begin letting customers know about what happened until three weeks after learning the details.

That delay is in line with a trend that causes concerned individuals to assert that affected companies aren’t being sufficiently prompt and transparent.

For example, Facebook waited two years before notifying customers about data obtained by Cambridge Analytica, also a third-party company. Then, there’s Equifax, the credit monitoring company that didn’t alert consumers until weeks after one of the most massive breaches in recent history happened.

It’s important to realize, though, that U.S. laws require companies to tell consumers about breaches, but don’t get specific about timeframes. Abnormally long delays put companies at risk of scrutiny by federal authorities and queries about why disclosures didn’t happen more efficiently.

The Potential Risk of Data Breaches as Companies Depend on Partnerships

The Access Group incident illustrates how it can become more challenging to maintain control of data when using external providers to take care of some aspects of a business.

Although none of the involved companies engaged in malicious actions, that won’t always be the case for future data-related mishaps.

ShareTweet
Previous Post

Kaspersky Lab discover critical vulnerabilities in a popular industrial protocol, affecting products from multiple vendors

Next Post

16,500 Student Loan Borrowers' Information Exposed in Data Leak

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol