DisclosureLens
Social EngineeringEducationEducationPhishingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedPIIIdentity (basic)EducationLowContained

Simpson University

bd_54e9b8db13f45bb1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Sep 17, 2021

Filed

Jun 9, 2022

To disclose

38 weeks

Affected

9state residents only

Linked

5 filings

Confidence

65%
Full breach record for Simpson University

Simpson University notified affected individuals of a data breach involving unauthorized access to employee email accounts between July 29, 2021, and September 17, 2021. The incident, likely caused by phishing, exposed names and education records. The university secured accounts, engaged forensic investigators, and offered one year of Experian IdentityWorks credit monitoring.

Incident timeline

undetected · 50 days
discovery → filing · 38 weeks / 265 days

Jul 29, 2021

Begins

Sep 17, 2021

Discovered

Jun 9, 2022

Filed

vs. sector median

+31 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGJun 9 · first
Montana State AGJun 9 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.