NEW YORK –The Princeton Review Inc accidentally posted names, birth dates, ethnicity, assessment scores, and other sensitive information about more than 100,000 students on a public portion of its Web site.
The data was meant to be protected by a password, the New York tutoring company told The New York Times for a Tuesday article.
The exposure was discovered by a rival of Princeton Review's that gave the Times an anonymous tip. Princeton Review removed the information from the public portion of its site Monday after it was contacted by the newspaper.
“As soon as I found out about this security issue we acted immediately to shut down any access to this information,” Stephen C. Richards, its chief operating officer, told the Times. The company has begun reviewing its security procedures, he said.
Mike Haro, an analyst at the Internet security firm Sophos PLC, suggested in the article that companies store sensitive and public data on separate computers.
"We are finding that companies today don't change until they have experienced the pain of a data breach that is exposed to the public," he said.
Princeton Review had the student data because it had been hired by several school systems to measure and try to improve academic performance. Hundreds of separate files were exposed, some containing information about tens of thousands of students.











