fbpx

Nelnet Servicing Data Breach Class Action

Nelnet Servicing, LLC is a student loan servicer. The complaint for this class action alleges that Nelnet failed to take sufficient measures to safeguard the personally identifiable information (PII) of current and former student loan borrowers and others it held in its files, leading to a data breach. The complaint alleges that Nelnet also did not notify the individuals affected in a timely manner.

The Nationwide Class for this action is all persons living in the US whose PII was compromised in the 2022 data breach announced by Nelnet Servicing in August 2022.

The complaint quotes Nelnet’s Privacy Policy as saying, “Nelnet takes careful steps to safeguard customer information. … We maintain reasonable and appropriate physical, electronic, and procedural safeguards to guard your Nonpublic Personal Information (NPI) and Personally Identifiable Information (PII), and we regularly test those safeguards to maintain the appropriate levels of protection.” It also claims to “regularly train our employees on privacy, information security, and their obligation to protect your information.”

According to the notices it sent out, Nelnet discovered the data breach on July 21, 2022, when it found that an unauthorized party had gained access to information on its network. At that time, the complaint alleges, the company did not notify the individuals whose information had been stolen but instead chose “to address the incident in-house by implementing other safeguards to some aspects of its computer security. It then simply resumed its normal business operations.”

More than a month later, on or around August 26, 2022, the complaint alleges, Nelnet notified state attorneys general and the affected individuals. The notice said that the unauthorized parties had had access to Nelnet’s system from sometime in June 2021 to July 21, 2022—more than a year, and, the complaint alleges, “a very long time for an unauthorized actor to be permitted access … without detection.”

The complaint claims that more than 2.5 million people were affected and that the PII stolen included full names and Social Security numbers. “Upon information and belief,” the complaint alleges, “the PII was not encrypted prior to the Data Breach.”

The complaint also alleges, “In response to the Data Breach, Nelnet claims it has further secured [its] systems to protect the private information. Nelnet admits additional security was required, but there is no indication whether these steps are adequate to protect” the information in its systems from here on.

Nelnet had obligations to those who had entrusted it with their information, the complaint says, to keep the data safe. The complaint alleges that “Nelnet failed to uphold its data security obligations” which means that the individual victims will be at risk of identity theft and financial fraud for years to come.

Article Type: Lawsuit
Topic: Privacy

Most Recent Case Event

Nelnet Servicing Data Breach Complaint

September 2, 2022

Nelnet Servicing, LLC is a student loan servicer. The complaint for this class action alleges that Nelnet failed to take sufficient measures to safeguard the personally identifiable information (PII) of current and former student loan borrowers and others it held in its files, leading to a data breach. The complaint alleges that Nelnet also did not notify the individuals affected in a timely manner.

Nelnet Servicing Data Breach Complaint

Case Event History

Nelnet Servicing Data Breach Complaint

September 2, 2022

Nelnet Servicing, LLC is a student loan servicer. The complaint for this class action alleges that Nelnet failed to take sufficient measures to safeguard the personally identifiable information (PII) of current and former student loan borrowers and others it held in its files, leading to a data breach. The complaint alleges that Nelnet also did not notify the individuals affected in a timely manner.

Nelnet Servicing Data Breach Complaint
Tags: Exposing Private Information, Exposure to cyber crime, Your Privacy