HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
Sage International Network of Schools
bd_806891d74912e1e6 · schema v1 · pii pii-v1
Full breach record for Sage International Network of Schools →Sage International Network of Schools reported a data security incident in Idaho affecting 331 residents. Unauthorized access occurred between July 22 and August 28, 2024, compromising two employee email accounts. Affected data included names, Social Security numbers, driver's license numbers, and financial account information. Sage engaged forensic investigators, secured accounts, and provided one year of credit monitoring via Experian to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_2a6dd59a9d5c665eMontana State AGfiled 2024-11-26Verified by operator
- bd_0a6b283f8485c69fIdaho State AGfiled 2024-10-09(48d gap)Candidate
Source provenance
- Source URL
- https://www.ag.idaho.gov/content/uploads/2024/11/Sage-International-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 26, 2024
- Raw hash
- af8b8923962adba82f3a829d17c60d3e1f3157463773c54bcabe989682ec3dda
Reporting entity
- Name
- Sage International Network of Schoolsnorm: sage international network of schools
Victim entity
- Name
- Sage International Network of Schoolsnorm: sage international network of schools
Incident
- Discovered
- Aug 26, 2024
- Materiality determined
- —
- Notification sent
- Nov 26, 2024
- Affected individuals
- 331
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the Idaho Attorney General’s OfficeNotified the Idaho Office of Risk ManagementNotified the Idaho Chief Information Security Officer
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 13 weeks(92 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.