HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTEDUCATIONMediumContained
National Student Clearinghouse
bd_3c0bc77e712651d4 · schema v1 · pii pii-v1
Full breach record for National Student Clearinghouse →National Student Clearinghouse notified individuals of a data breach involving its third-party provider, Progress Software, and its MOVEit Transfer solution. An unauthorized party obtained files containing personal information (name, DOB, SSN, student records) on or around May 30, 2023. The Clearinghouse was informed on May 31, 2023, and confirmed exfiltration on June 20, 2023. The organization engaged cybersecurity experts, coordinated with law enforcement, patched the software, and offered two years of identity monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_cf3b44f0d9c611cdLeak Sitecl0pfiled 2023-06-14(99d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_116e7610d8f2a768Washington State AGfiled 2023-09-21Verified by operator
- bd_f56f2ba4dc387770Oregon State AGfiled 2023-09-21Verified by operator
- bd_2a4b3c8c4d73dde1Maine State AGfiled 2023-08-31(21d gap)Verified
- bd_b407d20f148d3694Montana State AGfiled 2023-08-31(21d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 21d gap
- bd_b5e4fea795fb28f9Vermont State AGfiled 2023-08-31(21d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574028
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2023
- Raw hash
- 2803bda911732843072f615ee14fd562d97abff58e5cb4b310753c8b8898d873
Reporting entity
- Name
- National Student Clearinghousenorm: national student clearinghouse
- Domain
- studentclearinghouse.org
Victim entity
- Name
- National Student Clearinghousenorm: national student clearinghouse
- Domain
- studentclearinghouse.org
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEDUCATION
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 16 weeks(113 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.