The Board of Governors of the Colorado State University System
bd_442e2ef79000f25c · schema v1 · pii pii-v1
Full breach record for The Board of Governors of the Colorado State University System →The Board of Governors of the Colorado State University System (CSU) notified the New Hampshire Attorney General of a security event involving third-party vendors Pension Benefits Information, LLC (PBI) and the National Student Clearinghouse (NSC). The Clop threat actor exploited a zero-day vulnerability in Progress Software's MOVEit Transfer software to exfiltrate data. While CSU's own systems were not directly impacted, 19,344 individuals whose data was held by vendors on behalf of CSU were affected, including 37 New Hampshire residents. CSU issued community notices and vendors provided two years of complimentary credit monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
May 29, 2023
Begins
Jul 10, 2023
Discovered
Aug 14, 2023
Scope determined
Aug 17, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Montana State AGClopbd_d5be50961858899d2023-08-16 · +1dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.