HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Syracuse University
bd_05b34336f4bd933f · schema v1 · pii pii-v1
Full breach record for Syracuse University →Syracuse University notified the New Hampshire Attorney General of a security incident involving unauthorized access to two disbursement office email accounts between November 11-15, 2021. The breach affected 26 New Hampshire residents, whose names and Social Security numbers were potentially accessed. Syracuse secured the accounts, investigated, and began notifying affected individuals on March 28, 2022, offering one year of credit monitoring through Experian.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_9d537454055110c5Montana State AGfiled 2022-03-28Candidate
- bd_9e4a1a41cbf3953bMaine State AGfiled 2022-03-28Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/syracuse-20220328.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2022
- Raw hash
- 8f1c4f1742de7f8e413ae139fa983c69a3f291890f2388eee373dc272e25c9d3
Reporting entity
- Name
- Syracuse Universitynorm: syracuse university
Victim entity
- Name
- Syracuse Universitynorm: syracuse university
Incident
- Discovered
- Feb 14, 2022
- Materiality determined
- —
- Notification sent
- Mar 28, 2022
- Affected individuals
- 26
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.