HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Kent State University
bd_3ef514dcaae36a26 · schema v1 · pii pii-v1
Full breach record for Kent State University →Kent State University notified Vermont AG of a third-party data breach involving vendor Keffer Development Services, LLC. An unauthorized party used brute-force methods to access administrative credentials for the Athletic Trainer Services (ATS) platform, exposing student-athlete PII including names, DOBs, SSNs, and health data. Kent State convened an IR team, reset passwords, and mandated stricter controls for Keffer. Complimentary credit monitoring was offered. No Kent State systems were directly compromised.
Vermont clock✗ VT AG >45 bday32 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-07-25-kent-state-university-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2024
- Raw hash
- cb27d7d52557d6d54ae34a9317b277fd75ab0f1b7030f0b4c12cb1b2669490c6
Reporting entity
- Name
- Kent State Universitynorm: kent state university
Victim entity
- Name
- Kent State Universitynorm: kent state university
Incident
- Discovered
- Dec 14, 2023
- Materiality determined
- —
- Notification sent
- Jul 24, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1110 Brute ForceT1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified Vermont Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 32 weeks(224 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.