HackingStolen CredentialsCapture Stored DataCustomer Data InvolvedTargetedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Educational Computer Systems, Inc.
bd_766edf08d53cf6d6 · schema v1 · pii pii-v1
Full breach record for Educational Computer Systems, Inc. →Educational Computer Systems, Inc. (ECSI) disclosed a data breach affecting student/borrower tax forms (1098-E/1098-T) for University of Pennsylvania. Unauthorized access occurred between Oct 29, 2023, and Feb 12, 2024, via the guest tax search functionality. ECSI took the service offline, engaged a cybersecurity firm, and offered credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/university-pennsylvania-20240524.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 24, 2024
- Raw hash
- 067cf33bda1a307d8b2bb87506669240e619a5993bd64bf228daaf767f3452b5
Reporting entity
- Name
- Educational Computer Systems, Inc.norm: educational computer
Victim entity
- Name
- Educational Computer Systems, Inc.norm: educational computer
Incident
- Discovered
- Feb 12, 2024
- Materiality determined
- —
- Notification sent
- Apr 1, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.