The Colorado State University System
bd_32d0b46dab913a85 · schema v1 · pii pii-v1
Full breach record for The Colorado State University System →2 incidents on filePension Benefit Information, LLC (PBI) disclosed a data breach involving the MOVEit Transfer software vulnerability exploited by an unauthorized third party on May 29-30, 2023. The attacker downloaded PII, including names and government IDs, from PBI servers. PBI patched systems, investigated, and offered 24 months of credit monitoring. The incident is linked to the global Progress Software MOVEit vulnerability.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Jul 16, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_82d87ba1222f93e52023-07-13 · +3dCandidate
- Indiana State AGbd_85a691363233b3f02023-07-12 · +4dVerified
- Oregon State AGbd_2bbe91f60022e01e2023-08-12 · +27dVerified
- Maine State AGbd_7f9f1e65e6466ece2023-08-16 · +31dVerified
Show 1 more filing ↓Show fewer ↑up to 32d gap
- Massachusetts State AGbd_3d26be5ba564a8c22023-08-17 · +32dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jul 12 (IN), last Aug 17 (MA) — a 36-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.