Infosec in brief Hogwarts doesn’t teach an incantation that could have saved Harry Potter publisher Scholastic from feeling the power of an online magician who made off with millions of customer records - except perhaps the wizardry of multifactor authentication. Scholastic, publisher of the US editions of the Harry Potter series and The Hunger Games, along with other children's book series like The Magic School Bus and Goosebumps, was added to the Have I Been Pwned database last week after it emerged a self-described "furry" hacker - not associated with the other furry hackers, they claim - breaching an employee portal and exfiltrating about eight million items of data. The Daily Dot, which spoke to the hacker who identified themselves by the handle "Parasocial," said they gained access to the employee portal after stealing login credentials from a Scholastic employee whose system was infected with malware. The data Parasocial stole, which was reviewed by the Daily Dot, contained 4,247,768 unique email addresses and a mix of names, phone numbers and home addresses for US-based customers. More than one million of the compromised records belonged to educational contacts - (i.e., teachers and administrators), while the rest reportedly belonged to parents. The Daily Dot reported that parents are prompted to enter the names of their children when they register with the publisher. Luckily for those whose data was Accio'ed out of the Scholastic database, Parasocial isn't a Death Ea...
Datacus extractus: Harry Potter publisher breached without resorting to magic
The Register
·Brandon Vigliarolo
·Published Jan 20, 2025
·Updated
Affected Software
3 affected components
Planet Technology WGS-804HPT industrial ethernet switches
Qlik Sense Enterprise for Windows=prior to August 2023 Patch 2
Scholastic Employee Portal
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach impacting Scholastic, the publisher of Harry Potter, where millions of customer records were compromised.
2
What security implications are discussed?
The breach highlights vulnerabilities in online security practices, particularly the potential for unauthorized access to sensitive customer information.
3
What products or software are affected by the breach?
The breach affects the Scholastic Employee Portal, Planet Technology WGS-804HPT industrial ethernet switches, and Qlik Sense Enterprise for Windows prior to August 2023 Patch 2.
4
What measures could have prevented this data breach?
The article implies that stronger cybersecurity protocols and practices could have mitigated the risk of such a breach.
5
What actions should customers take following this incident?
Customers are advised to monitor their accounts for suspicious activity and change passwords, particularly those associated with Scholastic services.