Thousands of pupils' personal data at risk in website hack
The Information Commissioner’s Office (ICO) has found a school in Hampshire in breach of the Data Protection Act (DPA) after the personal details of nearly 20,000 people were put at risk when the school’s website was hacked.
According to an undertaking signed by Bay House School, computer hackers, including at least one of its own pupils, accessed the school’s internal information management system via an attack on the school’s remotely-hosted website.
In March, hackers gained access to the system after discovering that a member of staff used the same password to log into the school’s web and management systems. Despite Bay House School having a policy in place to prohibit the use of duplicate passwords, the school did not have checks in place to ensure the policy was adhered to.
