DisclosureLens
HackingEducationEducationStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDMediumContained

Bristol Community College

bd_3fb72d1d873b8bb2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 23, 2022

Filed

May 9, 2023

To disclose

20 weeks

Affected

7state residents only

Linked

6 filings

Confidence

66%
Full breach record for Bristol Community College4 incidents on file

Bristol Community College experienced unauthorized network access between Dec 14-23, 2022. Forensic review confirmed removal of full names and government IDs (SSN, driver's license). The college engaged external cybersecurity professionals, restored systems, and reported to federal authorities. Affected individuals were offered 12 months of Experian IdentityWorks credit monitoring. Approximately 3,760 Rhode Island residents were impacted.

Incident timeline

undetected · 9 days
discovery → filing · 20 weeks / 137 days

Dec 14, 2022

Begins

Dec 23, 2022

Discovered

May 9, 2023

Filed

vs. sector median

+9 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 4 states

View merged incident ↗
Massachusetts State AGFeb 28 · first
Montana State AG+435d · this page

Pattern: first filing Feb 28 (MA), last May 10 (IN) — a 436-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.