DisclosureLens
MalwareTechnologyEducationInformationRansomwareStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedMulti-Stage ChainFinancial accountIdentity (basic)LowActive

The University of Vermont

bd_6ec74e8cd5547e8a · schema v1 · pii pii-v1

Severity

Low

Discovered

May 3, 2019

Filed

Jul 29, 2019

To disclose

12 weeks

Affected

670

Confidence

66%
Full breach record for The University of Vermont4 incidents on file

PrismRBS, a vendor providing e-commerce services for the University of Vermont Bookstore, experienced a security incident where an unauthorized party installed malicious software to capture payment card information. The incident affected transactions between April 13 and April 26, 2019. A total of 670 individuals were affected, including 27 New Hampshire residents. UVM notified the NH Attorney General and affected individuals on July 23, 2019. PrismRBS engaged forensic investigators and is offering one year of identity protection services.

Incident timeline

undetected · 20 days
discovery → filing · 12 weeks / 87 days

Apr 13, 2019

Begins

May 3, 2019

Discovered

Jul 29, 2019

Filed

vs. sector median

on median

Part of PrismRBS supply-chain incident (2019) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed670 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.