DisclosureLens
HackingEducationEducationVulnerability ExploitStolen CredentialsTargetedData EncryptedIdentity (basic)Government IDHealth (basic)PHIMediumContained

THE UCLA FOUNDATION

bd_0beb6d352a52c2b2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 18, 2017

Filed

Jul 31, 2017

To disclose

11 weeks

Affected

27state residents only

Confidence

67%
Full breach record for THE UCLA FOUNDATION

UCLA reported a cyberattack on a Summer Sessions server in May 2017. The incident potentially exposed student PII including SSNs, DOBs, and medical info. 27 NH residents were affected. UCLA notified residents and offered 12 months of identity protection. Forensic analysis did not confirm data acquisition, but possibility could not be ruled out.

Incident timeline

discovery → filing · 11 weeks / 74 days

May 18, 2017

Discovered

Jul 31, 2017

Filed

vs. sector median

+4 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed27 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.