June 25, 2021
As beforehand introduced, the College of Maryland, Baltimore (UMB) was afflicted by the the latest Accellion, Inc. file transfer equipment (FTA) info stability incident. Accellion FTA software program is made use of by many universities, federal government agencies and general public and non-public companies all-around the earth. UMB is continuing its endeavours to notify everyone whose particular information may have been concerned in the Accellion incident, as demanded by legislation.
Accellion is an information and facts technological know-how seller that provided UMB’s FTA. The FTA was used to allow for the transfer and receipt of delicate data as a result of a safe protocol. In accordance to Accellion, its FTA program was qualified by a danger actor group(s), starting in mid-December 2020. UMB stopped employing the Accellion FTA and switched to a various protected file transfer platform in February 2021.
Although UMB experienced been advised formerly by Accellion that Accellion had investigated and experienced not identified any signs that downloads had transpired, on March 29, 2021, UMB was educated that selected facts data files in its Accellion FTA experienced been posted on a cyber criminal’s website. UMB documented the incident to the FBI and is working with federal law enforcement officials. Exterior forensic industry experts are also performing diligently to look into and identify the full scope of the incident. There is no evidence that any UMB information technological know-how devices other than the FTA were impacted. On March 31, 2021, UMB began mailing letters to regarded impacted men and women. Soon after preliminary investigation, on April 22, 2021, UMB started to have interaction with point out officials pertaining to impacted agency information. Impacted files relate to specified social support, health, public well being and study actions carried out by UMB on behalf of several information entrepreneurs like:
- Office of Juvenile Products and services (DJS): A variety of contributors of Purposeful Loved ones Treatment.
- Maryland Office of Overall health (MDH): A variety of participants in the MDH Maryland Medicaid System.
- Maryland Section of Human Companies (DHS):
- Social Services Administration (SSA) – Different members in Proof Dependent Tactics involving youngster and loved ones therapy and compound abuse cure packages.
- Baby Help Administration (CSA) – Various men and women who get products and services by means of the Baby Assist Administration.
- Family Financial commitment Administration (FIA) – Various individuals in the Family Investment decision Administration’s (FIA) profit plans of DHS.
Notification letters are remaining despatched as probably impacted individuals are identified. The facts influenced differs commonly by person and in some cases incorporated names, addresses, date of beginning, demographic and/or overall health similar facts and other facts involved with participation in a selected program, evaluation or analyze. For some individuals, the personal details included bundled a Social Safety selection, and these people today are currently being furnished complimentary credit rating checking and identification theft protection services as demanded by regulation.
It is suggested that all persons generally, and as impacted by this incident, carefully keep track of economic account statements and credit stories and report any discrepancies to regulation enforcement. Added steerage that consumers can acquire to secure on their own can be found at: https://www.customer.ftc.gov/features/aspect-0014-id-theft.
UMB has recognized a toll-totally free simply call heart dedicated to answering questions about this incident. This phone heart is offered commencing June 29, 2021, at 855-867-0875, Monday – Friday, 9:00 AM to 9:00 PM EST (excluding holidays). Individuals who participated in the courses previously mentioned who have not obtained a detect letter within close to 3 weeks may wish to connect with to validate irrespective of whether they had been afflicted.
UMB will take very seriously the protection and privateness of particular information entrusted to us, and deeply regrets that this incident transpired and any concern this may possibly bring about.
Updates to this observe will be posted at https://www.umaryland.edu/accellion.