HackingStolen CredentialsTargetedPIIIDENTITY_BASICLowContained
Northern Arizona University
bd_1784938ad1208c8c · schema v1 · pii pii-v1
Full breach record for Northern Arizona University →Northern Arizona University notified consumers of unauthorized access to employee email accounts between Feb 7-8, 2022. Investigation confirmed some consumer information (name, [Extra2]) was present in affected accounts. NAU engaged forensic specialists, notified regulators, and offered credit monitoring.
Vermont clock✗ VT AG >45 bday14 months discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_56323daf5b34438dMontana State AGfiled 2023-04-05Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-05-northern-arizona-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 5, 2023
- Raw hash
- f024227dfff8a8bd89c81a7bf4952f642ee7d9810ae5a9211ac82a8772c82f6e
Reporting entity
- Name
- Northern Arizona Universitynorm: northern arizona university
Victim entity
- Name
- Northern Arizona Universitynorm: northern arizona university
Incident
- Discovered
- Feb 7, 2022
- Materiality determined
- Apr 5, 2023
- Notification sent
- Apr 5, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified pertinent state and/or federal regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 14 months(422 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.