|
Infinite Campus has provided the North Carolina Department of Public Instruction (NCDPI) with an update regarding its March cybersecurity incident impacting their Salesforce application. Infinite Campus will soon begin notifying impacted Public School Units (PSUs). While the majority of PSUs were not impacted, we want to share the latest information so you know what to expect and where to direct questions.
On March 18, an unauthorized actor gained access to an Infinite Campus corporate account and copied files from their Salesforce application, which is the company’s case management and ticket system. This is separate from the Student Information System (SIS). The compromised dataset included a small number of NCDPI and PSU support tickets containing personally identifiable information (PII) that were submitted to Infinite Campus to resolve technical issues with the system.
NCDPI has continued to coordinate with Infinite Campus about the impact to North Carolina data. On August 17, Infinite Campus notified NCDPI that they are planning to start sending notifications to impacted PSUs. These notifications will come directly from Infinite Campus and will include impacted individuals and data elements as well as templates to document the incident with Infinite Campus. Per Infinite Campus, the vast majority of PSUs were not impacted by this incident, and therefore will not receive an individual notification.
If you have questions on the information provided by Infinite Campus, please contact the Infinite Campus Support Team. NCDPI takes the security of our shared systems seriously and will continue to coordinate with Infinite Campus to keep you informed as this situation develops.
Previous communications about this incident
March 22: Infinite Campus Security Incident Awareness: No Impact to Student Data According to Infinite CampusMarch 24: Infinite Campus Security Incident Update
March 24: Infinite Campus Security Incident Update
|