MisusePrivilege AbuseEmployee Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENTHighContained
Purdue University
bd_76ff944ccd99f639 · schema v1 · pii pii-v1
Full breach record for Purdue University →Purdue Pharma L.P. notified the New Hampshire Attorney General of an incident involving a former employee who accessed a disk containing personal information of approximately 5,000 individuals, including 15 New Hampshire residents. The data included names, dates of birth, Social Security numbers, and pension information. The former employee attempted to email the data before leaving the company. Purdue recovered the disk, believes copies were deleted, and provided two years of identity theft protection services to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5,000 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/purdue-pharma-20080509.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 9, 2008
- Raw hash
- b89647dbbf8e4a3cfc224889ad87650409c68dbb0628cb84edb93c2bc00a9c35
Reporting entity
- Name
- Purdue Universitynorm: purdue university
- Domain
- purdue.edu
Victim entity
- Name
- Purdue Universitynorm: purdue university
- Domain
- purdue.edu
Incident
- Discovered
- Mar 1, 2008
- Materiality determined
- —
- Notification sent
- Apr 14, 2008
- Affected individuals
- 5,000
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Time to disclose
- 10 weeks(69 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.