Exploit: Misconfiguration
British Council: Cultural Promotion & Language Testing
Risk to Business: 2.919 = Moderate
British Council, the global organization for promoting British culture and administrators of the International English Language Testing System (IELTS) exam, leaked over 144,000 files containing student records due to an unsecured Microsoft Azure blob. Researchers determined that the blob contained the personal information of hundreds of thousands of British Council English course learners and students from around the world. The group points to a contractor as the culprit for the leak.
Risk to Business: 2.906 = Moderate
Exposed data includes a student’s full name, email address, student ID, student status, enrollment dates, duration of the study, and other information.
Customers Impacted: Unknown
How it Could Affect Your Customers’ Business Cybercriminals have been having a field day going after education-related targets, a problem that is only growing worse.
Source: portswigger