Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIALMediumContained
Lexington School District Two
bd_55b87f24971c2fa4 · schema v1 · pii pii-v1
Full breach record for Lexington School District Two →Lexington County School District Two (Lexington 2) notified employees of a data breach involving W-2 information (names, SSNs, addresses, salary data) resulting from a social engineering scam. The incident impacted employees who received paychecks from the district in calendar year 2016. The district provided 12 months of free credit monitoring via CyberScout and notified multiple state and federal agencies, including SLED, the IRS, and the SSA.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2017/Lexington2Schools.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2017
- Raw hash
- 5bd9f729f38b017a3a7306afa5d2a4432ec11bdb09a4c18a4a2c9aae1f05165f
Reporting entity
- Name
- Lexington School District Twonorm: lexington school district two
- Domain
- lex2.community.highbond.com
Victim entity
- Name
- Lexington School District Twonorm: lexington school district two
- Domain
- lex2.community.highbond.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 27, 2017
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified SLED, the South Carolina Department of Revenue, the Social Security Administration, the IRS, the South Carolina Consumer Affairs Commission, the Consumer Protection Division, SC PEBA-Insurance and SC Retirement, and the SC Deferred Compensation plan
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.