DisclosureLens
Social EngineeringEducationEducationPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedPIIIdentity (basic)LowContained

Claremont Lincoln University

bd_3b63385b8c070dc3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 29, 2020

Filed

Dec 15, 2020

To disclose

24 weeks

Affected

1state residents only

Linked

4 filings

Confidence

64%
Full breach record for Claremont Lincoln University

Claremont Lincoln University notified individuals of unauthorized access to email accounts between June 1 and July 2, 2020, discovered on June 29, 2020. The incident involved phishing leading to credential compromise. Affected data included names and potential PII. No evidence of misuse was found. The university engaged forensic specialists, reset credentials, and offered 12 months of identity protection services.

Incident timeline

undetected · 28 days
discovery → filing · 24 weeks / 169 days

Jun 1, 2020

Begins

Jun 29, 2020

Discovered

Dec 15, 2020

Filed

vs. sector median

+14 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGDec 15 · first
Indiana State AGDec 15 · first
Montana State AGDec 15 · first · this page

Pattern: first filing Dec 15 (MA), last Dec 23 (NH) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.