DisclosureLens
HackingFinancial ServicesTechnologyFinanceVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDMediumContained

The Colorado State University System

bd_32d0b46dab913a85 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jul 16, 2023

To disclose

Affected

340state residents only

Linked

6 filings

Confidence

66%
Full breach record for The Colorado State University System2 incidents on file

Pension Benefit Information, LLC (PBI) disclosed a data breach involving the MOVEit Transfer software vulnerability exploited by an unauthorized third party on May 29-30, 2023. The attacker downloaded PII, including names and government IDs, from PBI servers. PBI patched systems, investigated, and offered 24 months of credit monitoring. The incident is linked to the global Progress Software MOVEit vulnerability.

Incident timeline

May 29, 2023

Begins

Jul 16, 2023

Filed

This filing is one of 6 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 32d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗
Indiana State AGJul 12 · first
Washington State AG+4d · this page

Pattern: first filing Jul 12 (IN), last Aug 17 (MA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.