HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Kaplan North America, LLC
bd_43bbc55f2a1fdb41 · schema v1 · pii pii-v1
Full breach record for Kaplan North America, LLC →Kaplan North America, LLC notified South Carolina regulators of an unauthorized access incident occurring between Oct 30 and Nov 18, 2025. The incident exposed names, SSNs, and driver's license numbers. Kaplan engaged external IT specialists and law enforcement, and offered Experian IdentityWorks to affected individuals.
This filing is one of 11 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_03ac6b2ac5b6d4a6Indiana State AGfiled 2026-03-17Candidate
- bd_1e887c69b831ca2bCalifornia State AGfiled 2026-03-17Verified
- bd_3af6a5c8e815660bMaine State AGfiled 2026-03-17Verified
- bd_5195761b433bf377New Hampshire State AGfiled 2026-03-17Verified
Show 6 more filings ↓Show fewer ↑up to 1d gap
- bd_6cd40678378733bbIowa State AGfiled 2026-03-17Verified
- bd_7eccbae29faca690Washington State AGfiled 2026-03-17Verified
- bd_9cd5c500ae4a6563Delaware State AGfiled 2026-03-17Verified
- bd_a1a2590136ab7eddVermont State AGfiled 2026-03-17Verified
- bd_dde3052cb27cb9c5Oregon State AGfiled 2026-03-17Verified
- bd_2163f3082d7a92d9Texas State AGfiled 2026-03-18(1d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2026/Consumer%20Letter%20-%20Kaplan%20North%20America%2C%20LLC.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2026
- Raw hash
- fb8a6ce22958bbe9c0e024614d67769827c457325ef6c14b198a6358067d84e9
Reporting entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Victim entity
- Name
- Kaplan North America, LLCnorm: kaplan north america
- Domain
- kaplan.com
Incident
- Discovered
- Feb 21, 2026
- Materiality determined
- —
- Notification sent
- Mar 17, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Alerted law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.