Full Report
The Pennsylvania State Education Association (PSEA) has sent breach notifications to over 500,000 current and former members
Analysis Summary
# Incident Report: Pennsylvania Schools Union Data Breach (PSEA)
## Executive Summary
In July 2024, the Pennsylvania State Education Association (PSEA) suffered a major data breach resulting in the compromise of personal information belonging to over half a million current and former members. The incident, suspected to be caused by the Rhysida ransomware group, exposed sensitive Personally Identifiable Information (PII) and financial details. The organization completed its investigation and began notification in early 2025.
## Incident Details
- **Discovery Date:** Sometime after July 6, 2024 (Investigation finalized February 18, 2025)
- **Incident Date:** July 6, 2024
- **Affected Organization:** Pennsylvania State Education Association (PSEA)
- **Sector:** Education/Union
- **Geography:** Pennsylvania, USA
## Timeline of Events
### Initial Access
- **Date/Time:** July 6, 2024
- **Vector:** Unauthorized threat actor access (Implied Ransomware/Extortion activity)
- **Details:** An unauthorized threat actor successfully gained access to PSEA systems and "acquired" member personal information.
### Lateral Movement
- *Details regarding lateral movement were not specified in the provided summary.*
### Data Exfiltration/Impact
- Personal information belonging to 517,487 individuals was acquired by the threat actor.
- Compromised data included a combination of: full name, date of birth, driver’s license/state ID, SSN, account numbers, PINs, security codes, passwords, routing numbers, payment card details (number, PIN, expiration date), passport numbers, taxpayer ID numbers, and health/medical insurance information.
### Detection & Response
- **Detection:** The organization became aware of the incident and initiated an investigation.
- **Response actions taken:** PSEA conducted an investigation concluding on February 18, 2025, followed by breach notification to affected individuals (as reported around March 20, 2025).
## Attack Methodology
- **Initial Access:** Unauthorized access mechanism unknown, but strongly suggested to be related to a ransomware campaign.
- **Persistence:** *Not specified.*
- **Privilege Escalation:** *Not specified.*
- **Defense Evasion:** *Not specified.*
- **Credential Access:** Compromise included usernames and passwords.
- **Discovery:** *Not specified.*
- **Lateral Movement:** *Not specified.*
- **Collection:** Gathering of PII, financial details, and health information.
- **Exfiltration:** Exfiltration of acquired data occurred prior to the investigation conclusion.
- **Impact:** Large-scale exposure and potential misuse of PII and financial data.
## Impact Assessment
- **Financial:** *Not specified.*
- **Data Breach:** 517,487 individuals impacted. Data included SSNs, driver's licenses, payment card data, medical information, and full login credentials (username/password).
- **Operational:** None explicitly mentioned, other than the investigation and notification process.
- **Reputational:** Significant negative impact due to the scale and sensitivity of the exposed data related to union members.
## Indicators of Compromise
*No specific IOCs (IPs, domains, hashes) were provided in the source material.*
- **Network indicators:** None specified (defanged).
- **File indicators:** None specified.
- **Behavioral indicators:** Unauthorized acquisition/exfiltration of member data from PSEA systems.
## Response Actions
- **Containment:** *Specific containment measures taken were not detailed.* It is inferred that access was eventually revoked following discovery and investigation.
- **Eradication:** *Specific eradication steps were not detailed.*
- **Recovery actions:** Conducting comprehensive investigation (completed Feb 18, 2025) and issuing breach notifications to all affected members advising on potential next steps.
## Lessons Learned
- The volume and sensitivity of member data stored by the PSEA created a significant, high-value target for threat actors.
- The forensic investigation and confirmation of the breach took approximately 7 months after the incident occurred (July 6, 2024, to February 18, 2025).
- The involvement of a known ransomware group (implied Rhysida) suggests potential data extortion tactics.
## Recommendations
- Immediate enhancement of controls protecting systems holding PII and financial data.
- Review and potentially redesign authentication mechanisms, especially for administrative or member data interfaces (e.g., implement mandatory MFA, enforce strong password policies).
- Formalize and accelerate forensic readiness and incident response plans to reduce the time between intrusion and official notification.
- Audit third-party relationships if the access vector involved external vendors or service providers often associated with Ransomware-as-a-Service actors.