Description of the breach:
The company hosting our “BirdID” service (https://birdid.no) has experienced a data breach which could potentially include personally identifiable information (PII). The attackers have gained access to the server in a way which could potentially allow them to download the user database without leaving traces.
Therefore, any personally identifiable information in the user database could be compromised. For students, this information includes submitted exams, exam results, and the student’s personal identification number.
All indications so far point towards this being an automated attack aimed at several websites suffering from the same vulnerability, and not a specific attack on the BirdID service or the PII stored in its database. However, due to the nature of the attack, we cannot rule out the possibility of the attackers downloading information from the user database.
The vulnerability has now been removed and this type of attack will not succeed if tried again.
I am a registered user. What do I have to do?
Next time you visit the BirdID site, you will be required to reset your password. If you have reused the same password on other sites, we recommend changing the password on all relevant sites.
How can I get more information?
Please visit this page to read Nord University’s Privacy Statement. If you have further questions, please contact behandlingsansvarlig@nord.no.