National Student Clearinghouse security incident

MOVEit/Cl0p. Data on millions of US students across thousands of schools exposed.

Last modified

Summary

  • Environment: Education services
  • Operational impact: Data on millions of US students across thousands of schools exposed
  • Financial impact: No financial figure is established by the reviewed source evidence
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2023, National Student Clearinghouse experienced an incident in its education services environment. The retained source describes the attack path as follows: MOVEit/Cl0p. [1]

The documented consequence was: Data on millions of US students across thousands of schools exposed. [1]

Impact

  • Documented impact: Data on millions of US students across thousands of schools exposed. [1]
  • No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.

Threat Group & Attack Vector

The retained source describes the attack path as follows: MOVEit/Cl0p. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • Cl0p — identified in the supported attack description. [1]

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The retained source reports coordination with law enforcement as part of the incident response. [1]

This account is bounded to National Student Clearinghouse notification. Details absent from that evidence are left unresolved rather than inferred. [1]