HackingVulnerability ExploitCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
LEE UNIVERSITY
bd_300a9184d4bcd081 · schema v1 · pii pii-v1
Full breach record for LEE UNIVERSITY →Lee University notified the New Hampshire Attorney General of a data security incident discovered in March 2024 involving a third-party software vulnerability. The breach may have exposed personal information, including SSNs, of approximately 139 New Hampshire residents (students, donors, and employees). Lee University engaged cybersecurity experts, contained the incident, and offered identity theft protection services to affected individuals.
Leak gap clock✗ Leak >180d12 months discovery → filing
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 341 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7e6cb9d5990cf549Montana State AGfiled 2025-03-25Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lee-university-20250325.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2025
- Raw hash
- 7131936765003804496f85cd92a74a5fb0b0a0a50eaaaba075b1009b717da165
Reporting entity
- Name
- LEE UNIVERSITYnorm: lee university
Victim entity
- Name
- LEE UNIVERSITYnorm: lee university
Incident
- Discovered
- Mar 22, 2024
- Materiality determined
- Mar 19, 2025
- Notification sent
- Mar 24, 2025
- Affected individuals
- 139
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella, Office of the Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 months(368 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.