Scholastic Breached

A hacker known as “Parasocial” recently breached Scholastic, the prominent education and publishing company, compromising data of approximately 8 million individuals, as reported by the Daily Dot.

Scholastic is a major global source of educational materials for pre-K to grade 12, providing both print and digital resources. It also publishes beloved children’s book series such as Harry Potter, The Hunger Games, Clifford the Big Red Dog, and Goosebumps.

The hacker presented the stolen data, allegedly obtained from an employee portal, to the Daily Dot. The compromised information includes names, email addresses, phone numbers, and home addresses, primarily of U.S.-based customers and educational contacts; however, not all entries contain complete details.

Of the total entries, about 1,048,576 are categorized as educational contacts. Users registering on Scholastic’s website can sign up as parents, teachers, or administrators, with parents required to provide their children’s full names and teachers their school affiliation.

After filtering out duplicates, the leak reveals 4,247,768 unique email addresses. The Daily Dot found several social media profiles matching names and states of residence from the leaked data, all linked to individuals working in education.

Parasocial claimed to have accessed the data by stealing login credentials from an employee infected with malware, stating they could have extracted more information but were restricted by an export limit on Scholastic’s server. A screenshot shared with the Daily Dot showcased the employee portal, which included various sections for employee information, sales quotas, inventory management, and invoices.

The hacker expressed that their actions were driven by boredom and stated they have no plans to release the data publicly. They criticized Scholastic’s security measures, remarking, “To Scholastic; lol get pwned. This is a lesson to be learned the hard way. Don’t let your customers take the hit for your security failures, use MFA,” referring to multi-factor authentication.

Additionally, Parasocial made a nod to the furry community by requesting a shout-out to “the puppygirl hacker polycule.” The furry community, known for its interest in anthropomorphic animal characters, has a notable presence in tech circles. While groups like the now-defunct SiegedSec, known for high-profile breaches, previously identified as furry hacktivists, Parasocial denied any connection to them.

A Scholastic representative stated that the company is investigating the incident, emphasizing, “Scholastic takes the security of our customers’ data seriously with extensive systems and protocols, and are investigating this claim thoroughly.”

Scholastic Breached

Follow us on social media

Check out other reports

Scholastic Breached

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top