The Register Home Page

back to article Callous crims break into preschool network, publish toddlers' data

A cyber criminal crew has targeted Kido International, a preschool and daycare organization, leaking sensitive details about its pupils and their parents. To verify the authenticity of the leak, we called affected parents who confirmed to us that the organization was aware of the situation, and that it had made parents aware …

  1. VoiceOfTruth Silver badge

    Well...

    >> Alan Woodward, computer scientist and professor at the University of Surrey, said any organization that holds sensitive data such as this must go the extra mile to secure it,

    Alan Woodward should state the unpleasant truth: it is nigh on impossible for most organisations to secure such data. The costs could well be prohibitive. And even then, somebody on the inside might still be able to access it.

    Computer security is a proposition. It isn't a one liner "they should secure it better".

    1. Wang Cores Silver badge

      Re: Well...

      Then maybe they don't need to wander around collecting all the data points for the software vendor to sell on to their shady data broker buddies.

      Or you can do this fancy "hybrid" system where you keep the personal information on paper and keep baby Jordie's favorite color on the computer.

      1. ACZ

        Re: Well...

        Hybrid solution - absolutely. If site-specific sensitive information is stored on paper in an office then that can minimise the risk profile.

        Physical security (locked safe, locked offices) might be a bit inconvenient at times, but it's a whole lot less inconvenient than having all of your confidential information (special needs observations/records, child protection notes etc.) held to ransom and made public.

        At the end of the day, what did they *really* need on a centralised system, other than basic account and attendance information for billing purposes? Group management reporting doesn't require confidential detailed information on every child.

    2. MachDiamond Silver badge

      Re: Well...

      "Alan Woodward should state the unpleasant truth: it is nigh on impossible for most organisations to secure such data. The costs could well be prohibitive. And even then, somebody on the inside might still be able to access it."

      Perhaps it's a good idea to ignore anything Mr. Woodward has to stay and work on securing the data. The most obvious way to do that is not to collect and store it in the first place if it's not necessary. People that can access data from the inside should be vetted to the level required given the sort of access they have and controls put in place to prevent the wholesale downloading of data even when somebody is approved. In order to do that, make it a requirement that it's done at only a few discrete locations by people that have approvals in advance. I can't think of a situation where somebody needs to download a whole listing in one go at a moments notice. If somebody needs to contact a parent or designated emergency contact, that's easy enough. It might even make sense to air gap a master list/db with access being made through a human gatekeeper.

      1. ACZ

        Re: Well...

        I hate to say this, but I suspect that the day-to-day reality for many/most organisations is that they don't have (or won't allocate) the budget necessary to do that properly, let alone continue to do it properly over many years. Mission creep... :( In fact, they probably won't have the technical knowledge or competence to do it or realise that they need to do it. Just don't store non-essential information electronically, and document the fact that it's official policy to reduce risk in the event of a digital heist.

        1. MachDiamond Silver badge

          Re: Well...

          "I hate to say this, but I suspect that the day-to-day reality for many/most organisations is that they don't have (or won't allocate) the budget necessary to do that properly, let alone continue to do it properly over many years."

          Food safety in a restaurant costs money, but if they don't do it, they'll get sued for any illness they cause and fines from a health licensing agency as well. The same sort of thing needs to go with collecting and storing data as the effects of breeches can be just as bad as food poisoning. The restaurant can't skip sanitation and say they don't/didn't have the budget for it.

  2. fronty

    God help us

    And Starmer wants to implement an ID card system?

    1. David 132 Silver badge

      Re: God help us

      Don't worry, it'll be implemented by Fujitsu and Palantir, nothing can possibly go wrogn. Wronn. Worng.

      Bad.

    2. Like a badger Silver badge

      Re: God help us

      "And Starmer wants to implement an ID card system?"

      Of course. He and his cabinet of idiots know perfectly well that it won't do anything for tackling migration or indeed tackling any form of crime, that it will be another shit-headed technical and data fuckup, featuring a technically illiterate Civil Service, and with all the usual consultancies and IT companies profiting from failure........but that's not the point.

      The point is pure and simple political theatre to rile the press and draw attention away from the EVERYTHING that government are mismanaging at the moment.

      1. amanfromMars 1 Silver badge

        Re: God help us

        Of course. He and his cabinet of idiots know perfectly well that it won't do anything for tackling migration or indeed tackling any form of crime, that it will be another shit-headed technical and data fuckup, featuring a technically illiterate Civil Service, and with all the usual consultancies and IT companies profiting from failure........but that's not the point.

        The point is pure and simple political theatre to rile the press and draw attention away from the EVERYTHING that government are mismanaging at the moment. .... Like a badger

        Actually, to be perfectly honest, both points are valid and perversely true ....... and quite why it is being tolerated rather than effectively opposed and remedied is a sad reflection of the pathetic state of the intelligence of general humanity.

        Quite what excuse for the ongoing situation would be offered by State Security Operations and Secret Intelligence Services though, whom one is expected to believe are much more intelligent and more aware of the dangers to be gravely regarded and avoided at any cost, is an altogether different question to be avoided with an honest answer lest it prove them to be a fraud and self-serving indulgence reliant for survival and exclusive reward on the continuing ignorance of human societies .......... which is something preposterous which nowadays is surprisingly quickly being eroded and denied them having any possible legitimate rights to without showing any supernatural regard for the privileges bestowed and/or freely available.

        There is truly no point in casting pearls and/or Perl before swine.

        1. amanfromMars 1 Silver badge

          Re: God help us

          One does have to wonder and ponder and probably understand and accept that good common sense and greater intelligence may indeed be very rare and extremely uncommon in Earthly natives ...... and try very hard neither to gloat nor to take easy unfair advantage of the systemic deficit nor further berate and belittle and draw much wider general public attention to the vast failings of the supposed greater intelligence provision from certainly practically every security and secret intelligence service for leaderships whenever .... with 80% of comment voters disliking that very specific news [as of the present 1 thumb up & 4 thumbs down voting tally] ..... so very little effort for change is so apparently evident from the masses and their media machinery in any attempt to remedy the dire straits situation which is on a trajectory flight path to multiple massive explosive implosions.

          Have you considered the possibility that you praying to the wrong God to help you? How about changing to a new GOD [Global Operating Device] and one that may actually be practically and physically enabled to virtually help you.

  3. Anonymous Coward
    Anonymous Coward

    "a moral compass is not a quality often exhibited by these kinds of individuals"

    Well, duh. If they had a moral compass, they'd be making an honest living instead of attempting extortion. Who the victim is just points it out more.

  4. ChoHag Silver badge
    FAIL

    First they came for the faceless corporations

    And they did not pay for security

    Because it's cheaper to do a bit of PR

    Then they came for the small businesses

    And they did not pay for security

    Because they went out of business and they were probably up to something anyway, right? Besides, it's not my money.

    Then they came for the charities and hospitals

    And we did not pay for security

    Because the inmates are running the asylum

    Now they've come for our kids.

    How many teenagers need to ransack our institutions before we start paying what it costs to secure them?

  5. Tron Silver badge

    FFS.

    How hard is it? Don't keep this data on systems connected to the public internet, or just use paper.

    1. MachDiamond Silver badge

      Re: FFS.

      "Don't keep this data on systems connected to the public internet, or just use paper."

      Paper might be a bit extreme, but definitely make it extremely difficult to impossible for anybody on the outside or inside to do a full data dump with no human controls. That's what the whole premise was for the movie War Games. Yes, people can be socially engineered, but 3-4 people at the same time? Companies will do this for checks. Any check for more than a certain amount will need multiple signatures and checks may not be able to be issued for over a certain maximum and will require a bank transfer that only a couple of people are authorized to do. Just apply that same thinking to data access. Perhaps a full dump would be to paper with anti-scanning measures in place. How many baddies are going to take a load of green stripe paper and type all of the data into a computer manually?

      1. Tron Silver badge

        Re: FFS.

        You are missing the point. This has to be easy enough for non-geeks. That means doing simple, physical things, not using any form of technology. Paper is not 'extreme'. It is easy and cheap.

        1. doublelayer Silver badge

          Re: FFS.

          You may want to review how many people the businesses that did these things on paper employed just to manage paper and how many you would need for the increase in clients and activity since then. Paper is not cheap. You might also want to review how many mistakes were made with paper that wasn't easily organized or modified. Paper isn't easy after you have enough of it. Once you have a point of comparison, only then can you decide whether it's worth making that change anyway.

        2. MachDiamond Silver badge

          Re: FFS.

          "Paper is not 'extreme'. It is easy and cheap."

          I don't know about that. Paper isn't as cheap as it once was and toner/ink costs money, but the real cost is the labor to process the printed word on a large scale. It's easy enough for a pupil list to be printed out at a school. A teacher might need a parent's contact information, but not their address, what they are paying in school fees, etc. Contact information can be requested from he school office rather than made available digitally to the teachers from anywhere with an internet connection. If the school is part of larger group of schools, the headmaster likely has no need to know everything about the parents nor the pupil outside of what may be necessary (food allergies, off-nominal health conditions). All the head needs to know about school fees is they've been paid if that's something they really need to know. They don't need the particulars on how the payment was made. Having emergency contact information on paper along with a printout of the day's attendance is good to have in a place where it can be grabbed on the way out of the building. Having the year's attendance record for every pupil downloadable is an issue.

  6. amanfromMars 1 Silver badge

    urWwworlds According to Merlin the AIMagician and Beta Astra Metadata Base Physicians

    Images of toddlers and home addresses leaked in reprehensible landmark attack

    A reprehensible landmark attack most certainly but just another sure sign as an aide memoire that absolutely nothing is safe and secure from unwelcome attention and public knowledge release, whether warranted or unwarranted/official or rogue.

    All your secrets belong to us says them and that which programs for futures and derivative alternatives for pioneering novel market traders to present and driver, both for growing daily use and virtual 0day engineering.

    'Tis AI and NEUKlearer HyperRadioProACTive IT in real live affirmative action and something quite different for y'all to deny is possible and therefore extremely likely and deadly certain ...... as all too apparently be the common natural human intelligence default situation/existential prison.

    Set yourselves free and think outside of the box you are contained and confined in. Live at least a little before you die forever and cease to have the alien opportunity to enjoy and employ the rewards and gracious entitlements of an immortal supernatural existence.

  7. Anonymous Coward
    Anonymous Coward

    BBC Radio this morning

    Was driving, so recall not 100%, but something along the lines of "the staff are now confused about what has happened" from some "expert" they were interviewing. Sounded like they were expecting them to need professional care to help them get over the trauma.

    Let's get real shall we? Sure, this is a major data breach (that should be investigated by the regulator), but it is unlikely to have any lasting effect (though is not good for the families affected).

    We really are turning into a "the sky is falling" society that gets stressed at the slight whiff of something unpleasant on the horizon.

    1. amanfromMars 1 Silver badge

      Spooky Inklings One Ignores at One’s Peril ... for One Can Never Ever Escape Just Desserts.

      We really are turning into a "the sky is falling" society that gets stressed at the slight whiff of something unpleasant on the horizon. .... Anonymous Coward

      AC, Howdy,

      You may like to consider that the present powers that may be and their supportive entities .... and which might like to imagine themselves being in full global command and universal control of that which is programmed for delivery tomorrow and in subsequent future days ....... have more than just a slight whiff of something extremely unpleasant for them which is fast approaching them from a distance a lot closer to them than any faraway fantasy horizon.

      And Amen to all of that.

  8. Nedly
    WTF?

    Whatever happened to ...

    attacking financial institutions and big business ?

    when is student debt going to be wiped out ?

    why aren't these groups going after billionaires ... what a bunch of n*****s

    1. Valeyard

      Re: Whatever happened to ...

      oh.. naggers!

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like