HackingCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICPIILowContained
CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT INDIA PRIVATE LIMITED
bd_6335ccbbbad76b8a · schema v1 · pii pii-v1
Full breach record for CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT INDIA PRIVATE LIMITED →Cambridge University Press & Assessment experienced a cybersecurity incident involving unauthorized access to a network segment of its Australian subsidiary. Suspicious activity was identified on June 5, 2024, with the breach window occurring between June 3 and June 7, 2024. The incident involved personal information, including names and addresses. The company engaged forensic experts, notified law enforcement, and enhanced security controls. Affected individuals are offered two years of credit and identity monitoring.
California clockDiscovered Jun 5, 2024 → Notified Apr 8, 2025307d ✗ CA 60-day late46 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_376a18b384effbd9Leak Siteinc_ransomfiled 2024-06-24(303d gap)Verified
- bd_4ca07a68d8bd05d6Leak Siteinc_ransomfiled 2024-06-05(322d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_796965d352b1ce94Maine State AGfiled 2025-04-23Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601784
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2025
- Raw hash
- 0e30303f90a2a7c00a0e0e8f1461bca24abea91f8b17f09fa72915356b5d1f5b
Reporting entity
- Name
- CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT INDIA PRIVATE LIMITEDnorm: cambridge university press assessment india private
- Domain
- cambridge.org
Victim entity
- Name
- CAMBRIDGE UNIVERSITY PRESS & ASSESSMENT INDIA PRIVATE LIMITEDnorm: cambridge university press assessment india private
- Domain
- cambridge.org
Incident
- Discovered
- Jun 5, 2024
- Materiality determined
- —
- Notification sent
- Apr 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 46 weeks(322 days from discovery to filing)
- Compliance flags
- CA 60-day late · 307dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 5, 2024→ Notified: Apr 8, 2025307d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.