HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Georgia Institute of Technology
bd_61a2018aa0d12a4e · schema v1 · pii pii-v1
Full breach record for Georgia Institute of Technology →The Georgia Institute of Technology disclosed a data breach affecting California residents. Unauthorized access to an internal database occurred between December 14, 2018, and March 22, 2019, via a web server vulnerability. Affected data included names, addresses, Institute IDs, dates of birth, and Social Security numbers. Georgia Tech engaged forensic investigators, secured the web server, and notified the U.S. Department of Education. Affected individuals were offered one year of complimentary credit monitoring and identity protection services through ID Experts.
California clockDiscovered Mar 22, 2019 → Notified May 22, 201961d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5e308b1e230109a2Washington State AGfiled 2019-05-22Candidate
- bd_69d11ad986ca01d3Oregon State AGfiled 2019-05-22Verified
- bd_e98ad89400414581Montana State AGfiled 2019-05-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-147461
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 22, 2019
- Raw hash
- 2fce1abf8c600df293c1653d60599be755a9b6c5bb2f19adac63d3144bc9bca0
Reporting entity
- Name
- Georgia Institute of Technologynorm: georgia institute of
- Industry
- education
Victim entity
- Name
- Georgia Institute of Technologynorm: georgia institute of
- Industry
- education
Incident
- Discovered
- Mar 22, 2019
- Materiality determined
- —
- Notification sent
- May 22, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notified the U.S. Department of Education
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(61 days from discovery to filing)
- Compliance flags
- CA 60-day late · 61d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 22, 2019→ Notified: May 22, 201961d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.