Social EngineeringEducationEducationPretextingCapture Stored DataCustomer Data InvolvedTargetedPIIFINANCIALLowResolved
Colorado State University - Pueblo
bd_61c4d57e333de213 · schema v1 · pii pii-v1
Full breach record for Colorado State University - Pueblo →On August 14, 2024, Colorado State University – Pueblo experienced a social engineering attack targeting university employees. An unauthorized third party manipulated staff members into providing access to an unprotected Excel spreadsheet containing student first and last names, CSU ID numbers, and current billing balances for approximately 11,079 individuals (2 Maine residents). No university or CSU System computer systems were breached. Electronic notifications were sent on August 18, 2024.
Maine clockDiscovered Aug 15, 2024 → Filed with AG Sep 5, 202421d ✓ ME AG ≤30d21 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f5d8040d4a3cf6daNew Hampshire State AGfiled 2024-09-05Verified
- bd_e08271f0e5d8cffbVermont State AGfiled 2024-09-04(1d gap)Verified
- bd_4cbc52f0b9c4f0faIndiana State AGfiled 2024-08-18(18d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fc8ffa3a-3c77-4245-84ab-4e1f88080657.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2024
- Raw hash
- a4520ab327c8bc8f2880b2215950dd283636924b66eff18f74d8656280407d71
Reporting entity
- Name
- Colorado State University - Pueblonorm: colorado state university pueblo
- Domain
- csupueblo.edu
- Industry
- Education
Victim entity
- Name
- Colorado State University - Pueblonorm: colorado state university pueblo
- Domain
- csupueblo.edu
- Industry
- Education
- Industry
- Educationllm
Incident
- Discovered
- Aug 15, 2024
- Materiality determined
- —
- Notification sent
- Aug 18, 2024
- Affected individuals
- 2
- Data types
- PIIFINANCIAL
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 Phishing
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Aug 15, 2024→ Filed with AG: Sep 5, 202421d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.