CSIDB logo
Incident

Public School and Education Employee Retirement Systems of Missouri

Incident posture

Attack window
Sep 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-23 00:00

Linked entities

Victim
Public School and Education Employee Retirement Systems of Missouri
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Public School and Education Employee Retirement Systems of Missouri experienced unauthorized access to an employee’s email account, which was disabled within an hour of detection. The breach exposed names, retirement account numbers, and some dates of birth for approximately 349,000 employees and retirees. This incident occurred separately from another unrelated security issue involving teacher Social Security numbers discovered via a state agency website vulnerability. The email compromise appeared to result from external hacking activity, though specific access methods were not disclosed in notifications.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 11, 2021, the Public School and Education Employee Retirement Systems of Missouri (PSRS/PEERS) experienced a security incident involving unauthorized access to an employee’s email account. An external threat actor compromised the account and maintained access for less than one hour before IT personnel detected the intrusion and disabled the account. The breach was contained swiftly after the organization’s security team received an alert prompting immediate action. Investigation revealed the compromised email account contained sensitive personal information of PSRS/PEERS members, including full names and retirement system account numbers. A subset of affected individuals also had their dates of birth exposed. The organization did not specify the exact method of initial access or whether multi-factor authentication (MFA) was enabled on the account at the time of the incident.

PSRS/PEERS notified 349,246 employees and retirees of the breach, confirming the exposure of personally identifiable information but clarifying that Social Security numbers (SSNs) were not stored in the affected email account. This incident occurred separately from another contemporaneous event involving a vulnerability on a Missouri state agency website, where a St. Louis Post-Dispatch reporter discovered publicly accessible teachers’ SSNs. While both incidents impacted Missouri educators, the email compromise at PSRS/PEERS constituted a distinct external breach rather than an inadvertent data exposure. The organization submitted a copy of its breach notification letter to the Maine Attorney General’s Office as part of regulatory compliance efforts. No details were provided regarding forensic findings about the attacker’s identity or motives, nor were specific technical measures implemented post-incident disclosed beyond the account deactivation.

Sources

Sources available to members: 1 source.

CSIDB