HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
Paul Smith’s College
bd_278f4e894c372785 · schema v1 · pii pii-v1
Full breach record for Paul Smith’s College →Paul Smith’s College notified consumers of a data breach where an unauthorized individual accessed the network on August 27, 2022. The incident was discovered on January 26, 2023. Personal information, potentially including medical data, was accessed. The College secured accounts, engaged outside cybersecurity professionals, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
Vermont clock⏱ VT AG >14 bday22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
A leak claim by avoslocker about this victim predates this filing by 53 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_9ecc4e3f224e37bcLeak Siteavoslockerfiled 2022-12-26(53d gap)Verified by operator
Regulatory filings (3) · sorted by filing gap
- bd_1975423568504eb4Maine State AGfiled 2023-02-16(1d gap)Verified by operator
- bd_93340885d0e3fae7Montana State AGfiled 2023-02-16(1d gap)Verified by operator
- bd_749a2116957e8916Montana State AGfiled 2023-04-17(59d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-02-17-paul-smiths-college-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 17, 2023
- Raw hash
- 16450fb734c21e67e974e595babb6d17970329c7e51e75a53f720e83dc939fb9
Reporting entity
- Name
- Paul Smith’s Collegenorm: paul smith s college
Victim entity
- Name
- Paul Smith’s Collegenorm: paul smith s college
Incident
- Discovered
- Jan 26, 2023
- Materiality determined
- —
- Notification sent
- Feb 17, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- VT AG >14 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.