Education Ministry Investigation Concludes on Major Data Leak of Special Needs Students
Translated & summarized from NEWSru Israel by baba
Israel's Privacy Protection Authority concluded an administrative review into the Ministry of Education after a data leak exposed personal and medical details of 21,000 ultra-Orthodox special needs students. The leak occurred in May 2024 when ministry employees created an electronic form with an improperly secured data file accessible via a shared link. The data, including sensitive medical information, was widely disseminated by March 2025. The authority stressed the need for robust data security for sensitive information, particularly concerning minors.
The story in 6 lines · by baba
- A data leak exposed personal and medical information of 21,000 ultra-Orthodox special needs students in Israel.
- The leak originated from a Ministry of Education system in May 2024, discovered in March 2025.
- Sensitive data included identification, addresses, school details, and medical information on disabilities.
- An electronic form created by ministry employees had improperly secured access to the data file.
- The Ministry of Education suggested an isolated error in access rights configuration caused the breach.
- The Privacy Protection Authority emphasized the need for high information security for sensitive databases.
Israel's Privacy Protection Authority has concluded an administrative review into the Ministry of Education following a significant leak of personal and medical data concerning approximately 21,000 students in the ultra-Orthodox special education system, known as "Hinuch Meyuchad." The investigation, initiated in March 2025 after media reports, found that the breach originated from a system used by the ministry.
The leaked information included identification details, home addresses, school information, religious affiliation, and sensitive medical data detailing disabilities or health limitations for each student. The review determined that in May 2024, ministry employees created an electronic form to streamline the process of assigning these students to educational institutions. To facilitate this, they exported data from the ministry's system into a file containing the personal details of the 21,000 students.
This file was intended to be an internal resource for the form, allowing it to retrieve information. However, the form itself was set to public access, meaning anyone with the link could use it, and the link could be forwarded. Crucially, the data file was also accessible via an open link without password protection, enabling the form to pull data and allowing anyone with the link to view and download it.
In May 2024, the link to the form was distributed to relevant officials in ultra-Orthodox educational institutions via both work and personal email addresses. By March 2025, it became public that the data file had fallen into unauthorized hands and was widely disseminated. The Ministry of Education suggested the incident was likely an isolated error in access rights configuration for one of the forms, which allowed an unauthorized individual to discover the data file through search engines after accessing the link.
The ministry's database from which the information was extracted holds sensitive data on over 100,000 individuals and requires a high level of information security. The Privacy Protection Authority reiterated the obligation of government bodies and database owners to safeguard personal information, especially sensitive data of minors.
