Rensselaer Polytechnic Institute
bd_1cade7c054a76fac · schema v1 · pii pii-v1
Full breach record for Rensselaer Polytechnic Institute →2 incidents on fileRensselaer Polytechnic Institute (RPI) notified students that a third-party vendor, Athletic Trainer System (ATS), experienced a cyber incident between Jan 2020 and Jan 2021. A perpetrator used a 'data miner' tool to collect info from accounts with vulnerable passwords. RPI was notified in Nov 2023. Data included names, DOBs, injury info, and potentially SSNs. RPI mandated MFA and is migrating to a new system.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2020
Begins
Nov 17, 2023
Discovered
Feb 1, 2024
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_747790e80bfa4e6e2024-02-01Verified
- Maine State AGbd_8d79f05ec7ca65d22024-02-02 · +1dVerified
- New Hampshire State AGbd_bb4e3de0601012b42024-02-02 · +1dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.