The Board of Governors of the Colorado State University System
bd_442e2ef79000f25c · schema v1 · pii pii-v1
Full breach record for The Board of Governors of the Colorado State University System →The Board of Governors of the Colorado State University System (CSU) notified the New Hampshire Attorney General of a security event involving third-party vendors Pension Benefits Information, LLC (PBI) and the National Student Clearinghouse (NSC). The Clop threat actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data. While CSU's own systems were not directly impacted, 19,344 individuals whose data was held by vendors on behalf of CSU were affected, including 37 New Hampshire residents. CSU issued community notices and vendors provided two years of complimentary credit monitoring through Kroll.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_d5be50961858899dMontana State AGfiled 2023-08-16(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/board-governors-colorado-state-university-system-20230817.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2023
- Raw hash
- e97f4c972fb727e68442d6f0b10f08d35bf372218c11fe1b9c1d544729b0565f
Reporting entity
- Name
- The Board of Governors of the Colorado State University Systemnorm: the board of governors of the colorado state university system
- Domain
- csusystem.edu
Victim entity
- Name
- The Board of Governors of the Colorado State University Systemnorm: the board of governors of the colorado state university system
- Domain
- csusystem.edu
Incident
- Discovered
- Jul 10, 2023
- Materiality determined
- Aug 14, 2023
- Notification sent
- Aug 17, 2023
- Affected individuals
- 19,344
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain· Clop
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- ClopExternalFinancial
- Regulator citations
- Providing written notice of this security event to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(38 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.