Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
May 30, 2025
No Result
View All Result
Concur News

Home » Pearson Confirms Cyberattack, Customer Data and Source Code Stolen

Pearson Confirms Cyberattack, Customer Data and Source Code Stolen

May 29, 2025
in Europe, Privacy, Regulation
Reading Time: 2 mins read
Pearson
Share on LinkedinShare on Whatsapp

Education company Pearson has confirmed a major cyberattack that exposed customer data and internal corporate information. The UK-based company, known for textbooks and digital education tools, said an unauthorized actor accessed part of its system earlier this year. Pearson discovered the breach and immediately began an investigation with the help of cybersecurity experts. The company also notified law enforcement and added new security measures to prevent future incidents.

Pearson stated that most of the stolen data is “legacy data,” meaning older records. According to the company, no employee data was affected. It plans to share updates directly with customers and partners.

Sources revealed the breach began in January 2025. Hackers accessed Pearson’s internal development tools using a security token found in a public Git configuration file. This file mistakenly exposed a GitLab Personal Access Token.

Consent Foundation

The attackers used the token to access Pearson’s source code. Inside the code, they found hard-coded credentials for cloud services like AWS, Google Cloud, and Snowflake. These credentials allowed them to steal large volumes of data over several months.

The stolen data reportedly includes customer records, financial details, support tickets, and internal source code. Pearson has not revealed how many users the breach affected but admitted the number could reach millions. The company also refused to say whether it paid any ransom.

Earlier this year, Pearson had disclosed a breach at its subsidiary PDRI. That incident is believed to be linked to the current attack.

Cybersecurity experts warn that exposing Git configuration files can lead to serious breaches. Developers are advised to secure these files and avoid storing access tokens or passwords in them.

Pearson has not said when affected users will be notified or what exact data was stolen. The investigation is still ongoing.

Tags: AI PrivacyData breachData privacyPrivacy

Related Posts

Aviral
Interview

Interview with Aviral Kulshrestha, Sharing Insights on Navigating GDPR and DPDPA Challenges

May 30, 2025
Vijayashankar Nagarajarao
Interview

Interview with Vijayashankar Nagarajarao (Naavi), Founder of FDPPI, Sharing Insights on Cyber Law, Data Privacy, and DPDPA

May 28, 2025
Star Health Data Scare: Breach, Backlash, and a ₹250 Crore Blow
India

Star Health Data Scare: Breach, Backlash, and a ₹250 Crore Blow

May 30, 2025
Database Leak
Global

Unsecured Database Leak Exposes 184 Million Login Records from Major Tech Platforms

May 28, 2025

RECOMMENDED NEWS

Coinbase data

Hackers Steal Coinbase User Data and tried to extort $20M

2 weeks ago
Shopify Data Privacy

Shopify Faces Revived Data Privacy Lawsuit in U.S. Appeals Court

1 month ago
Snapchat Privacy

Court Rejects Stay of Civil Proceedings in Snapchat Privacy Case

1 month ago
Udaipur Hosts Cybersecurity Awareness Session Focused on Data Protection and Digital Safety

Udaipur Hosts Cybersecurity Awareness Session Focused on Data Protection and Digital Safety

1 month ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data Safeguard Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR Generative AI google Hack Hacked Industry Interview Investigation Keyless Law online services penalty Personal data PII Press Release Privacy RTI Act Startek Tech giants Technology Training Trending

Trimtab Innovation Pvt. Ltd 701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager