HackingData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSMediumContained
Monmouth University
bd_346c38b67fb41663 · schema v1 · pii pii-v1
Full breach record for Monmouth University →Monmouth University notified the California AG of a data breach where an unauthorized third party accessed files from its network between Feb 5-13, 2026. The university discovered the incident on March 3, 2026. Affected data may include names, SSNs, driver's licenses, financial account numbers, medical information, and credentials. The university engaged forensic investigators, notified law enforcement, and is offering credit monitoring.
California clockDiscovered Mar 3, 2026 → Notified Jun 30, 2026119d ✗ CA 30-day late17 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_2f9fdb38c91c7c57Leak Sitepearfiled 2026-03-03(119d gap)Verified by operator
Regulatory filings (6) · sorted by filing gap
- bd_52b83bf7bc528fcdVermont State AGfiled 2026-06-30Verified
- bd_99ed51db4805dd73New Hampshire State AGfiled 2026-06-30Verified
- bd_ea41c7a62f5cf428Delaware State AGfiled 2026-06-30Verified
- bd_a0056bdb614e9c6aTexas State AGfiled 2026-07-01(1d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 29d gap
- bd_2f2dd8dfe15aba32Massachusetts State AGfiled 2026-06-01(29d gap)Candidate
- bd_fda40e176e033c82Massachusetts State AGfiled 2026-06-01(29d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625770
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2026
- Raw hash
- a334fb459137d08eb182b57b48ad9b5b7f193253f5e54fc2abfc4c0bef551bdc
Reporting entity
- Name
- Monmouth Universitynorm: monmouth university
- Domain
- monmouth.edu
Victim entity
- Name
- Monmouth Universitynorm: monmouth university
- Domain
- monmouth.edu
Incident
- Discovered
- Mar 3, 2026
- Materiality determined
- —
- Notification sent
- Jun 30, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(119 days from discovery to filing)
- Compliance flags
- CA 30-day late · 119dLeak >90dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 3, 2026→ Notified: Jun 30, 2026119d 30 calendar days CA 30-day late California Consumers notified: Jun 30, 2026→ AG copy submitted: Jun 30, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.