Social EngineeringPhishingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Syracuse University
bd_05a44b36da3cd578 · schema v1 · pii pii-v1
Full breach record for Syracuse University →Syracuse University reported a data security incident to the California Attorney General's Office involving unauthorized access to an employee's email account between September 24 and 28, 2020. The breach was attributed to a phishing attack. The university secured the account, engaged a cybersecurity firm, and notified affected individuals, offering one year of Experian IdentityWorks. The specific data accessed was redacted in the public notice as <<b2b_text_1(ImpactedData)>>, but the notice implies personal information was involved.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_aa2df12c61e3af5fMaine State AGfiled 2021-02-05Candidate
- bd_ef9604bdadc4fe71Montana State AGfiled 2021-02-05Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537804
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 5, 2021
- Raw hash
- 0473dff314f1ec4084947dbe9d6b1c27e5c6855b43f11710780f7c6d109c4f11
Reporting entity
- Name
- Syracuse Universitynorm: syracuse university
Victim entity
- Name
- Syracuse Universitynorm: syracuse university
Incident
- Discovered
- Sep 28, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.