Stanford University exposed files of 897 economics PhD applicants
- Organization
- Stanford University
- Exploit
- Misconfiguration
- Industry
- Higher Education
Stanford University notified 897 people who applied to its Department of Economics PhD program for 2022-23 admission that their application files had been exposed on the department's website. The university said it was told on January 24, 2023 that a folder holding the applications was reachable through the site because the folder's permission settings had been misconfigured.
Stanford's investigation found that unrestricted access began on December 5, 2022 and that the material was downloaded twice before access was cut off. The exposed files included names, dates of birth, home and mailing addresses, phone numbers, email addresses, race and ethnicity, citizenship and gender, together with supporting documents such as transcripts, personal statements, resumes and letters of recommendation. Some submissions also contained health information.
The university said Social Security numbers and financial details were not involved because application files did not hold that data. It also said the incident was confined to the economics PhD program and did not touch undergraduate admissions or other departments.
Access to the folder was restricted immediately, and the university's Information Security Office and Privacy Office opened an investigation. Stanford reported no evidence that the downloaded material had been misused, said it was revising its electronic file storage policies and retraining staff, and offered affected applicants 24 months of credit and cyberscan monitoring, identity theft recovery services and a $1 million insurance reimbursement policy.