• News/
  • https://www.theregister.com/2025/01/20/harry_potter_publisher_breach/

Datacus extractus: Harry Potter publisher breached without resorting to magic

The Register
·
Brandon Vigliarolo
·
Published Jan 20, 2025
·
Updated

Infosec in brief Hogwarts doesn’t teach an incantation that could have saved Harry Potter publisher Scholastic from feeling the power of an online magician who made off with millions of customer records - except perhaps the wizardry of multifactor authentication. Scholastic, publisher of the US editions of the Harry Potter series and The Hunger Games, along with other children's book series like The Magic School Bus and Goosebumps, was added to the Have I Been Pwned database last week after it emerged a self-described "furry" hacker - not associated with the other furry hackers, they claim - breaching an employee portal and exfiltrating about eight million items of data. The Daily Dot, which spoke to the hacker who identified themselves by the handle "Parasocial," said they gained access to the employee portal after stealing login credentials from a Scholastic employee whose system was infected with malware. The data Parasocial stole, which was reviewed by the Daily Dot, contained 4,247,768 unique email addresses and a mix of names, phone numbers and home addresses for US-based customers. More than one million of the compromised records belonged to educational contacts - (i.e., teachers and administrators), while the rest reportedly belonged to parents. The Daily Dot reported that parents are prompted to enter the names of their children when they register with the publisher. Luckily for those whose data was Accio'ed out of the Scholastic database, Parasocial isn't a Death Ea...

Read full article

Affected Software

3 affected components
Planet Technology WGS-804HPT industrial ethernet switches
Qlik Sense Enterprise for Windows=prior to August 2023 Patch 2
Scholastic Employee Portal

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach impacting Scholastic, the publisher of Harry Potter, where millions of customer records were compromised.

2

What security implications are discussed?

The breach highlights vulnerabilities in online security practices, particularly the potential for unauthorized access to sensitive customer information.

3

What products or software are affected by the breach?

The breach affects the Scholastic Employee Portal, Planet Technology WGS-804HPT industrial ethernet switches, and Qlik Sense Enterprise for Windows prior to August 2023 Patch 2.

4

What measures could have prevented this data breach?

The article implies that stronger cybersecurity protocols and practices could have mitigated the risk of such a breach.

5

What actions should customers take following this incident?

Customers are advised to monitor their accounts for suspicious activity and change passwords, particularly those associated with Scholastic services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203