The Student Loans Company (SLC) has apologised for mistakenly sending the email addresses of thousands of students to the wrong recipients.
The body said the addresses were included in an email sent to “other customers,” but the SLC could not go into any more details about who those customers were.
The snafu was the result of an administrative error, but no other personal student data was share, the SLC said.
According to the Daily Telegraph, around 8,000 students were affected by the breach.
The SLC is responsible for handing out student grants, delivering means-tested awards via its Student Finance England subsidiary.
The Information Commissioner’s Office said it was looking into the matter. “We have recently been made aware of a possible data breach which appears to involved the Student Loans Company,” a spokesperson told TWE. “We will be making enquiries into the circumstances of the alleged breach of the Data Protection Act before deciding what action, if any, needs to be taken.”
However, as the data is unlikely to be deemed particularly sensitive, or cause harm to individuals, it is unlikely the ICO will punish the SLC. No email correspondence was leaked and it appears no important personal data went amiss.
If passwords were leaked, the situation would be much more serious. Last month, YouPorn users were in a panic after a related service used by the porn site’s members was hacked. Passwords to that service were exposed and users were advised to change their login details for all sites they accessed using the stolen credentials.
How well do you know IT security? Test yourself with our quiz.
Welcome to Silicon UK: AI for Your Business Podcast. Today, we explore how AI can…
Japanese tech investment firm SoftBank promises to invest $100bn during Trump's second term to create…
Synopsys to work with start-up SiMa.ai on joint offering to help accelerate development of AI…
Start-up Basis raises $34m in Series A funding round for AI-powered accountancy agent to make…
Data analytics and AI start-up Databricks completes huge $10bn round from major venture capitalists as…
Congo files legal complaints against Apple in France, Belgium alleging company 'complicit' in laundering conflict…
View Comments
Does it matter?
Emails are regularly transferred server-server unencrypted anyways.
This was something that people understand, going wrong. There's a ton of other stuff that people don't understand that's much worse.
I won't be happy if I get loads of junk mail as a result. A list like this is pretty valuable to people wanting to target students.
I think it also matters as it indicates rather shoddy standards in data processing - hence what more may they have lost in the past, or what are likely to lose in the future?!