HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Carnegie Mellon University
bd_4b400de4cd0922bf · schema v1 · pii pii-v1
Full breach record for Carnegie Mellon University →Carnegie Mellon University detected suspicious activity on August 25, 2023, revealing unauthorized third-party access to a computer system. The attacker may have copied files containing names, social security numbers, and dates of birth. CMU disabled access to the files and collaborated with law enforcement. Affected individuals are offered 24 months of Experian IdentityWorks credit monitoring.
California clockDiscovered Aug 25, 2023 → Notified Jan 12, 2024140d ✗ CA 60-day late20 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_a73a836d2c2f9a93Indiana State AGfiled 2024-01-12Verified
- bd_d7e9b0ee37521eacVermont State AGfiled 2024-01-12Verified
- bd_e5516b04777ac61cMaine State AGfiled 2024-01-12Candidate
- bd_fa71a693bd407756Montana State AGfiled 2024-01-12Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579261
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2024
- Raw hash
- 95daf3428c71cd9f048255ddeb1476a100f9a789e647c3a3516115eeb5d08712
Reporting entity
- Name
- Carnegie Mellon Universitynorm: carnegie mellon university
Victim entity
- Name
- Carnegie Mellon Universitynorm: carnegie mellon university
Incident
- Discovered
- Aug 25, 2023
- Materiality determined
- —
- Notification sent
- Jan 12, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Collaborated with law enforcement
Compliance
- Time to disclose
- 20 weeks(140 days from discovery to filing)
- Compliance flags
- CA 60-day late · 140d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 25, 2023→ Notified: Jan 12, 2024140d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.