MalwareRansomwareData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
OKLAHOMA CITY UNIVERSITY
bd_2e2e6a888a8d8276 · schema v1 · pii pii-v1
Full breach record for OKLAHOMA CITY UNIVERSITY →On July 23, 2022, Oklahoma City University detected and stopped a network security incident where an unauthorized third-party infiltrated the network and encrypted data. The attacker obtained personal identifiable information including names, addresses, Social Security numbers, driver's license/state ID numbers, and passport numbers of current and prior students. The university secured its network, engaged forensic specialists, and reported the matter to law enforcement. Identity theft protection services are being offered to affected individuals.
California clockDiscovered Jul 23, 2022 → Notified Mar 20, 2023240d ✗ CA 60-day late35 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6972e211d95a9a0bMaine State AGfiled 2023-03-27Verified by operator
- bd_89dbdc38e2a2bb6cNew Hampshire State AGfiled 2023-03-27Verified
- bd_d486b04db48f14eaMontana State AGfiled 2023-03-27Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-564744
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 27, 2023
- Raw hash
- f25d4749f4fe01b184f6041fd7991e8e8e717d20f380b929c8037f496ab120ed
Reporting entity
- Name
- OKLAHOMA CITY UNIVERSITYnorm: oklahoma city university
- Domain
- okcu.edu
Victim entity
- Name
- OKLAHOMA CITY UNIVERSITYnorm: oklahoma city university
- Domain
- okcu.edu
Incident
- Discovered
- Jul 23, 2022
- Materiality determined
- —
- Notification sent
- Mar 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported this matter to law enforcement
Compliance
- Time to disclose
- 35 weeks(247 days from discovery to filing)
- Compliance flags
- CA 60-day late · 240dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 23, 2022→ Notified: Mar 20, 2023240d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.