[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1748i9jvneyw6":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":16,"seoTitleEn":29,"seoDescription":16,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882531c","poin-campus","PoinCampus Data Breach","poincampus","poincampus.com","2024-11-14T00:00:00.000Z","2025-02-04T00:29:41.000Z","2026-07-03T23:23:17.190Z","2026-07-18T23:56:14.910Z","Third party breach","",[],89116,"known",null,"unknown","Medium",[24,25,26,27],"Dates of birth","Email addresses","Names","Phone numbers","\u003Cp>The PoinCampus data breach is related to the exposure of user data belonging to the South Korea-based education platform during the November 2024 period. The scope includes approximately 89,116 unique email addresses. This record was treated as an education platform user data breach; the company, country, industry, website, and data class fields were realigned with the verified scope. It was marked as sensitive due to the date of birth and phone fields.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain the risk, scope, and action to the user. The website domain was kept as poincampus.com; a format that would cause https to appear twice on the link was not used because the protocol was not added. The country was corrected from United States to South Korea, and the sector was corrected to online learning platform.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are birth dates, email addresses, names, and phone numbers. The password or payment card field was not verified. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only supported fields were retained.\u003C\u002Fp>\u003Cp>In the context of the education platform, fake course, certificate, student account, or payment notification messages can appear convincing. An email address alone poses a risk of unwanted messages; when combined with a phone number, address, IP, date of birth, password, travel plans, partial card information, or device data, it becomes easier for an attacker to generate messages specific to the user. The risk assessment was conducted according to this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with record 89.116 dated November 2024. Confirmed areas were preserved while unconfirmed areas were excluded. The incident was not combined with datasets with similar names, incidents from different periods of the same company, or incorrect industry references.\u003C\u002Fp>\u003Cp>The registration is limited to the domain poincampus.com and has not been combined with other educational platforms. The domain name, company name, and industry information were kept in the narrowest correct context possible. In cases of uncertainty, the verified flag or website domain was set accordingly; thus, no uncertain brand responsibility was shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include PoinCampus students, course participants, and users who have opened an educational account. Matched users should also evaluate other accounts where they use the same email, phone number, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>Date of birth and phone information especially increase privacy and social engineering risk in student profiles. If there is a context of corporate email, educational account, hotel reservation, telecom subscription, gaming community, open source donation, or tracking software, the social engineering risk may increase. Details that appear correct are not a sign of trust on their own.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check education, certificate, course payments, and phone verification messages from the official platform. For records with a password field, all accounts using the same password should be updated; for records without a password field, the focus should be on risks related to email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages about shipping, account alerts, game rewards, support, donor notifications, travel reservations, security notifications, or subscription renewals should not be accepted without verification from an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary sharing of birth dates and phone numbers should be restricted on educational platforms, and unique passwords should be used for student accounts. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. A unique password for each service and two-factor authentication wherever possible should be the basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Educational platforms should protect the communication and birth date data of young users more strictly. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can lead the user to take wrong actions.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record with their email address. If a match is found, it should be assumed that the date of birth, phone number, name, and email information may be at risk; educational-themed messages should be verified. Not finding a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record has been verified and updated as sensitive. In this edit, data fields were left as English canonical classes, the user-visible description was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","PoinCampus Data Breach (89.1 Thousand Reported Records)","PoinCampus Data Breach. 89.1 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fpoincampus_com.webp",false,{"name":34,"sector":35,"country":36,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"PoinCampus","Education \u002F Online Learning Platform","South Korea"]