The targeted vendor, called Cleo, is a file transfer software used for Electronic Data Interchange with external entities, the letter said. CPS said they learned Feb. 8 that student data had been inappropriately accessed during the incident. As of now, there is no evidence to suggest that student data has been misused. The letter stated that the unauthorized party gained access to students' name, date of birth, gender and Chicago Public Schools student ID number. Although the incident is still being investigated, it is believed to affect current students as well as former students dating back to the 2017-2018 school year. CPS said no social security numbers, financial information, or health data were accessed during this incident. Students enrolled in federal Medicaid programs also had their Medicaid ID number and dates if program eligibility exposed. Medicaid ID numbers, also known as Recipient Identification Numbers, cannot be used to obtain a social security number. CPS said the incident has been reported to the appropriate law enforcement authorities, and they are continuing to assist with the investigation.
CONTINUE READING