HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
The New York Center for Research, Economic Advancement, Technology, Engineering and Science Corporation
bd_3260d20827c756c6 · schema v1 · pii pii-v1
Full breach record for The New York Center for Research, Economic Advancement, Technology, Engineering and Science Corporation →NY CREATES, SUNY Poly, and the Research Foundation for SUNY reported unauthorized access to file servers at their Albany, NY campus between Dec 13-14, 2022. An unauthorized party obtained files containing employee PII, including SSNs, driver's licenses, financial account numbers, and health information. The incident was contained, law enforcement was notified, and a cybersecurity firm was engaged. Affected individuals were offered one year of credit monitoring.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7f3959f8229075e8Vermont State AGfiled 2023-03-10Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/new-york-center-research-economic-advancement-20230310.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 10, 2023
- Raw hash
- c273f7b6672927b96eee8718fc5c1b85a73cc28b7a9279800de8203fbb4286b8
Reporting entity
- Name
- The New York Center for Research, Economic Advancement, Technology, Engineering and Science Corporationnorm: the new york center for research economic advancement technology engineering and science
Victim entity
- Name
- The New York Center for Research, Economic Advancement, Technology, Engineering and Science Corporationnorm: the new york center for research economic advancement technology engineering and science
Incident
- Discovered
- Dec 14, 2022
- Materiality determined
- Feb 6, 2023
- Notification sent
- Mar 10, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.