HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
San José State University
bd_19f2956475a360f0 · schema v1 · pii pii-v1
Full breach record for San José State University →On December 10, 2018, San Jose State University (SJSU) detected unauthorized access to a server operated by its auxiliary, SJSU Associated Students. The attacker accessed names, email addresses, usernames, and passwords. No SSNs, financial, or medical data were involved. SJSU blocked access, disabled credentials, and notified affected individuals on December 26, 2018. Remediation included migrating servers to SJSU infrastructure and conducting security assessments.
California clockDiscovered Dec 10, 2018 → Notified Dec 26, 201816d ✓ CA 60-day OK16 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-143171
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 26, 2018
- Raw hash
- 28816f6d84ddb90d68ed875b4e73edf9de4594faa8dec21e4f44b7e9aeeb8893
Reporting entity
- Name
- San José State Universitynorm: san jose state university
- Domain
- sjsu.edu
- Industry
- Education
Victim entity
- Name
- San José State Universitynorm: san jose state university
- Domain
- sjsu.edu
- Industry
- Education
Incident
- Discovered
- Dec 10, 2018
- Materiality determined
- —
- Notification sent
- Dec 26, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notification with California Attorney General
- Third party
- via SJSU Associated Students
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 16d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 10, 2018→ Notified: Dec 26, 201816d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.