HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Our Lady of the Lake University
bd_1c065fda0494c21a · schema v1 · pii pii-v1
Full breach record for Our Lady of the Lake University →Our Lady of the Lake University notified consumers of a data breach discovered on or around August 30, 2022. Unauthorized access resulted in the exfiltration of full names and Social Security Numbers. The university engaged outside cybersecurity professionals for investigation and is offering 12 months of complimentary credit monitoring and fraud assistance to affected individuals.
Vermont clock✗ VT AG >45 bday30 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by avoslocker about this victim predates this filing by 95 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b5e9475384f2db0aLeak Siteavoslockerfiled 2022-12-26(95d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_fd338da8a640ecfcMontana State AGfiled 2023-03-30(1d gap)Verified by operator
- bd_1dd46276fadaf169Maine State AGfiled 2023-04-10(10d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-03-31-our-lady-lake-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 31, 2023
- Raw hash
- b2d80072fa397e02f445037ab8b4efa55ad163a08739085b68528e0571940397
Reporting entity
- Name
- Our Lady of the Lake Universitynorm: our lady of the lake university
- Industry
- education
Victim entity
- Name
- Our Lady of the Lake Universitynorm: our lady of the lake university
- Industry
- education
Incident
- Discovered
- Aug 30, 2022
- Materiality determined
- —
- Notification sent
- Mar 31, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(213 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.