The Chronicle of Higher Education, Inc.
bd_109cd63629957e5b · schema v1 · pii pii-v1
Full breach record for The Chronicle of Higher Education, Inc. →3 incidents on fileThe Chronicle of Higher Education, Inc. disclosed that unauthorized parties exploited a server vulnerability to obtain administrative credentials and accessed a database containing hashed and salted passwords for online accounts on February 17, 2020. The incident was discovered on May 10, 2020, after an internal alert. The company took the server offline, engaged forensic investigators, and notified law enforcement. Affected users were prompted to change passwords, and the company implemented stronger hashing technology and replaced the affected server.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 17, 2020
Begins
May 10, 2020
Discovered
May 13, 2020
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_557eb7302a7faf952020-07-10 · +58dCandidate
Filing propagation · 2 filings
View merged incident ↗Pattern: first filing May 13 (CA), last Jul 10 (CA) — a 58-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.