HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
University of the People
bd_57d53b879077ad26 · schema v1 · pii pii-v1
Full breach record for University of the People →University of the People notified consumers of a data security incident in mid-January 2022. Unauthorized third parties accessed or exfiltrated files from a SharePoint platform between January 2 and January 10, 2022. The files contained personal information, including names and government IDs. UoPeople engaged third-party experts, enhanced security, and offered one year of credit monitoring.
Vermont clock✗ VT AG >45 bday15 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_7684067d9ceb71f9Montana State AGfiled 2023-04-04Candidate
- bd_970e1ff5835dd356New Hampshire State AGfiled 2023-04-04Verified
- bd_1d855dd1d17c87fbCalifornia State AGfiled 2023-04-05(1d gap)Verified
- bd_ac9b991feced758eMaine State AGfiled 2023-04-05(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-04-university-people-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2023
- Raw hash
- 9d4fe52c5c30813f345750040a6064b5c8b2bc43263dc7dea32059bafce2aa5b
Reporting entity
- Name
- University of the Peoplenorm: university of the people
Victim entity
- Name
- University of the Peoplenorm: university of the people
Incident
- Discovered
- Jan 15, 2022
- Materiality determined
- Apr 4, 2023
- Notification sent
- Apr 4, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 months(444 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.