HackingEducationEducationVulnerability ExploitCapture Stored DataSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIILowContained
LEE UNIVERSITY
bd_37ece777e49ea046 · schema v1 · pii pii-v1
Full breach record for LEE UNIVERSITY →In March 2024, Lee University (Cleveland, TN) experienced a security incident in which an external actor exploited a third-party software vulnerability, resulting in potential unauthorized download of university data. Discovery of the full scope was not completed until March 2025. Approximately 275 Maine residents were among 136,928 total individuals affected. Notification was sent March 24, 2025. IDX identity protection services were offered to affected individuals.
Leak gap clock✗ Leak >180d7 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by medusa about this victim predates this filing by 342 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_428da8b3973313dcLeak Sitemedusafiled 2024-04-17(343d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/250151eb-b98e-4fc1-bb70-caca5f6600ed.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 26, 2025
- Raw hash
- 361520888e674b6fff686fa7b8cfbaa2ae566ecb0fb984edf4c4ae40f5494246
Reporting entity
- Name
- LEE UNIVERSITYnorm: lee university
- Industry
- Education
Victim entity
- Name
- LEE UNIVERSITYnorm: lee university
- Industry
- Education
- Industry
- Educationllm
Incident
- Discovered
- Mar 19, 2025
- Materiality determined
- —
- Notification sent
- Mar 24, 2025
- Affected individuals
- 275
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- Leak >180dME AG ≤30d · 7d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 19, 2025→ Filed with AG: Mar 26, 20257d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.